Kyber is a ransomware operation that emerged publicly in 2025 and has been observed conducting coordinated cross-platform attacks against Windows and VMware ESXi environments. The operation has used distinct encryptors for different platforms, including a Rust-based Windows payload and a C++ ESXi/Linux payload, indicating deliberate support for enterprise virtualization and core file-server disruption within the same intrusion. Reported incidents show deployment of both variants in a single victim environment, consistent with efforts to maximize operational impact across virtual infrastructure and business-critical systems. Kyber’s ESXi-focused tooling is designed to target VMware datastores and can terminate virtual machines prior to encryption, while also altering management interfaces to display ransom messaging. The Windows variant includes anti-recovery and service-disruption functionality, including actions against backup- and database-related services, deletion of shadow copies, disabling of recovery options, and log clearing when executed with elevated privileges. An experimental capability to shut down Hyper-V virtual machines has also been reported, suggesting interest in broader virtualization-focused disruption beyond VMware. Kyber has been associated with claims of advanced cryptography, including references to Kyber1024 and hybrid encryption schemes. Reporting indicates that at least some Windows samples appear to implement the advertised hybrid cryptographic approach, while an analyzed ESXi sample did not actually implement the claimed post-quantum cryptography despite advertising it in ransom messaging. This suggests either uneven development maturity across platform variants or deliberate inflation of technical claims for intimidation and branding. The operation fits the broader ransomware ecosystem’s trend toward multi-environment targeting, rapid enterprise disruption, and extortion-driven monetization. High-confidence reporting supports capabilities including initial access through ransomware intrusion workflows, persistence in virtualized environments, defense evasion, post-exploitation actions, and data-centric extortion behavior. Kyber is best characterized as a financially motivated ransomware group or operation rather than a nation-state actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
15 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware operation experimenting with post-quantum cryptography and coordinated attacks across Windows and VMware ESXi environments.
A relatively new ransomware operation targeting Windows and VMware ESXi infrastructures, with specialized encryptors for each environment and destructive capabilities focused on virtualization platforms.
Cross-platform ransomware operations targeting Linux/ESXi and Windows environments, with coordinated deployment against virtualization infrastructure and file servers. The group uses dual-platform payloads, Tor-based ransom infrastructure, VM shutdown capabilities, and anti-recovery actions to maximize operational disruption.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.