Krybit is a financially motivated ransomware-as-a-service operation first observed in late March 2026. The group conducts double-extortion attacks, stealing data before encrypting victim systems and pressuring payment through a dedicated leak site on Tor. Public reporting indicates Krybit operates an affiliate model with revenue sharing and provides ransomware builders for Windows, Linux, VMware ESXi, and NAS environments. Available malware analysis has described the payload as Babuk-derived. Krybit has shown broad, opportunistic targeting rather than a narrow regional or sector focus. Victims have been claimed across dozens of countries, with reporting specifically identifying Germany, Spain, and Brazil among the most affected geographies. Sectors repeatedly associated with Krybit victimology include professional services, technology, manufacturing, financial services, government, health care, education, and industrial organizations. Documented intrusion and post-compromise behavior includes use of valid accounts and remote services for access, script-based execution, credential access, system and network discovery, data staging and exfiltration, defense evasion, and encryption for impact. Reporting also links Krybit to process injection and deletion of shadow copies prior to encryption. Victim communications and leak operations are routed through Tor hidden services. Krybit gained unusual public visibility in April 2026 after rival ransomware group 0APT breached its affiliate panel, exposing operational details including administrator and affiliate structure, plaintext credential storage, negotiation activity, and ransom demands. Krybit subsequently retaliated by compromising and defacing 0APT infrastructure and publishing 0APT operational data. Despite that exposure, Krybit continued victim posting through mid-2026 and was assessed as an emerging and active RaaS operation. No confirmed ties to a nation-state or previously established ransomware gang have been publicly identified. Known operator aliases reported from the leaked panel include KRYBIT and GREP.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
13 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
16 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a ransomware attack against nigeria.asa-international.com / ASA Nigeria.
Conducting a ransomware attack against DC Partner (Pty) Ltd in South Africa.
Conducting a ransomware attack against Country Motos S.A. de C.V. / Country Motors, a Mexican motorcycle dealership.
Conducting a ransomware attack against the Municipality of Rinxent in France.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.