Kyber
Kyber is a relatively new cross-platform ransomware family targeting Windows file servers and VMware ESXi/Linux environments. Public reporting places activity at least as early as December 2025, with Rapid7 analyzing coordinated Windows and ESXi payloads recovered from the same victim network in March 2026. The two variants shared a campaign ID and Tor-based negotiation/leak infrastructure, suggesting deployment by the same affiliate to maximize impact across server environments.
The Windows variant is a 64-bit Rust-based encryptor. High-confidence analysis indicates it uses AES-256-CTR for bulk file encryption and implements a hybrid key-protection scheme using X25519 and Kyber1024. Encrypted files are renamed with the .#~~~ extension and receive a fixed 0x744-byte trailer containing metadata and keying material; the trailer begins with magic bytes e12fa8c3. The sample analyzed used the ransom note read_me_now.txt / READ_ME_NOW.txt, embedded Kyber-related Rust dependencies, and included a Kyber1024-sized public key in the binary. It also registers encrypted-file handling via HKCR.#~~~ and HKCR\fucked.file, writes a custom icon to C:\fucked_icon\processed_file.ico, and launches anti-recovery commands including vssadmin, PowerShell/WMI deletion, wmic SHADOWCOPY DELETE, bcdedit, wbadmin, and wevtutil. Additional reported behavior includes terminating services associated with Exchange, VSS, backup, Veeam, SQL, and IIS, deleting shadow copies and backups, disabling recovery settings, clearing event logs, emptying the Recycle Bin, and an experimental Hyper-V shutdown feature.
The ESXi/Linux variant is a 64-bit C++ ELF tailored for VMware environments. It encrypts datastore contents under /vmfs/volumes, can enumerate and optionally terminate virtual machines, drops ransom notes, and can deface ESXi management interfaces including /etc/motd and VMware web UI pages. Encrypted files use the .xhsyw extension. Despite ransom-note claims of AES-256-CTR, X25519, and Kyber1024/ML-KEM, Rapid7 found this variant actually uses ChaCha8 for file encryption and RSA-4096 for key wrapping, with no evidence of real post-quantum cryptography in that sample.
Kyber’s ransom notes claim use of AES-256-CTR with X25519 and Kyber1024 for key generation, and one note gives victims one week to respond. Reporting and analysis indicate the operation has emphasized post-quantum branding, likely as intimidation or marketing, but only the Windows variant was confirmed to implement the advertised Kyber1024 path. Known infrastructure in the analyzed reporting includes the Tor chat portal mlnmlnnrdhcaddwll4zqvfd2vyqsgtgj473gjoehwna2v4sizdukheyd[.]onion and leak/blog site kyblogtz6k3jtxnjjvluee5ec4g3zcnvyvbgsnq5thumphmqidkt7xid[.]onion. As of April 22, 2026, public reporting cited one listed victim described as a large American defense contractor and IT services provider. Overall, Kyber is characterized as a specialized ransomware tool designed to cause severe operational disruption by simultaneously targeting Windows and virtualization infrastructure.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Techniques & procedures
5 distinct techniques documented for this family, organized by ATT&CK tactic.
Stealth
1 technique
Stealth
Impact
4 techniques
Impact
Encryption approaches are evolving toward optimized and selective models, including intermittent encryption and experimental cryptographic techniques.
...aggressive recovery inhibition (e.g., backup deletion, service termination)...
IOCs tracked for this family
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Recent activity
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Multi-platform ransomware targeting Windows and VMware ESXi, using Rust-based development, partial encryption, backup deletion, service termination, and selective use of Kyber1024 post-quantum cryptography.
Rust-based ransomware that encrypts files on Windows, appends the .#~~~ extension, drops a READ_ME_NOW.txt ransom note, inhibits recovery via tools like vssadmin/wmic/bcdedit/wbadmin/wevtutil, and uses a hybrid cryptographic design. The analyzed Windows variant uses AES-CTR-style bulk file encryption with HMAC-SHA256-style key/IV derivation and incorporates Kyber1024-sized encapsulation material plus active Curve25519/X25519 arithmetic in a fixed 0x744 trailer appended to encrypted files.
A ransomware strain described as a specialized tool capable of causing a complete operational blackout.
Ransomware that encrypts files using AES for bulk file encryption and then encrypts the AES key with a claimed post-quantum key encapsulation mechanism; the article suggests its post-quantum branding is primarily a psychological marketing tactic to pressure victims into paying.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.