Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
MalwareRansomware

Kyber

Kyber is a relatively new cross-platform ransomware family targeting Windows file servers and VMware ESXi/Linux environments. Public reporting places activity at least as early as December 2025, with Rapid7 analyzing coordinated Windows and ESXi payloads recovered from the same victim network in March 2026. The two variants shared a campaign ID and Tor-based negotiation/leak infrastructure, suggesting deployment by the same affiliate to maximize impact across server environments.

The Windows variant is a 64-bit Rust-based encryptor. High-confidence analysis indicates it uses AES-256-CTR for bulk file encryption and implements a hybrid key-protection scheme using X25519 and Kyber1024. Encrypted files are renamed with the .#~~~ extension and receive a fixed 0x744-byte trailer containing metadata and keying material; the trailer begins with magic bytes e12fa8c3. The sample analyzed used the ransom note read_me_now.txt / READ_ME_NOW.txt, embedded Kyber-related Rust dependencies, and included a Kyber1024-sized public key in the binary. It also registers encrypted-file handling via HKCR.#~~~ and HKCR\fucked.file, writes a custom icon to C:\fucked_icon\processed_file.ico, and launches anti-recovery commands including vssadmin, PowerShell/WMI deletion, wmic SHADOWCOPY DELETE, bcdedit, wbadmin, and wevtutil. Additional reported behavior includes terminating services associated with Exchange, VSS, backup, Veeam, SQL, and IIS, deleting shadow copies and backups, disabling recovery settings, clearing event logs, emptying the Recycle Bin, and an experimental Hyper-V shutdown feature.

The ESXi/Linux variant is a 64-bit C++ ELF tailored for VMware environments. It encrypts datastore contents under /vmfs/volumes, can enumerate and optionally terminate virtual machines, drops ransom notes, and can deface ESXi management interfaces including /etc/motd and VMware web UI pages. Encrypted files use the .xhsyw extension. Despite ransom-note claims of AES-256-CTR, X25519, and Kyber1024/ML-KEM, Rapid7 found this variant actually uses ChaCha8 for file encryption and RSA-4096 for key wrapping, with no evidence of real post-quantum cryptography in that sample.

Kyber’s ransom notes claim use of AES-256-CTR with X25519 and Kyber1024 for key generation, and one note gives victims one week to respond. Reporting and analysis indicate the operation has emphasized post-quantum branding, likely as intimidation or marketing, but only the Windows variant was confirmed to implement the advertised Kyber1024 path. Known infrastructure in the analyzed reporting includes the Tor chat portal mlnmlnnrdhcaddwll4zqvfd2vyqsgtgj473gjoehwna2v4sizdukheyd[.]onion and leak/blog site kyblogtz6k3jtxnjjvluee5ec4g3zcnvyvbgsnq5thumphmqidkt7xid[.]onion. As of April 22, 2026, public reporting cited one listed victim described as a large American defense contractor and IT services provider. Overall, Kyber is characterized as a specialized ransomware tool designed to cause severe operational disruption by simultaneously targeting Windows and virtualization infrastructure.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

MITRE ATT&CK

Techniques & procedures

5 distinct techniques documented for this family, organized by ATT&CK tactic.

Stealth

1 technique
T1070Indicator RemovalEvidence1

The Windows variant also terminates services, deletes backups, and attempts to eliminate recovery paths by clearing shadow copies and event logs.

Impact

4 techniques
T1486Data Encrypted for ImpactEvidence3

Encryption approaches are evolving toward optimized and selective models, including intermittent encryption and experimental cryptographic techniques.

T1489Service StopEvidence2

...aggressive recovery inhibition (e.g., backup deletion, service termination)...

T1490Inhibit System RecoveryEvidence2

...partial encryption strategies, and aggressive recovery inhibition (e.g., backup deletion, service termination)...

T1529System Shutdown/RebootEvidence1

One variant targets VMware ESXi, featuring datastore encryption and VM termination

INDICATORS OF COMPROMISE

IOCs tracked for this family

4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
2 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
2 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in app2 months ago
domain●●●●●●●●●●●●View more in app2 months ago
hash.sha256●●●●●●●●●●●●View more in app2 months ago
hash.sha256●●●●●●●●●●●●View more in app2 months ago
ACTIVITY FEED

Recent activity

8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

cyfirma otherNews
May 15, 2026
TRACKING RANSOMWARE : APRIL 2026 - CYFIRMA

Multi-platform ransomware targeting Windows and VMware ESXi, using Rust-based development, partial encryption, backup deletion, service termination, and selective use of Kyber1024 post-quantum cryptography.

Read more
derp ca blogNews
Apr 26, 2026
Kyber ransomware is not just post-quantum name-dropping | Derp

Rust-based ransomware that encrypts files on Windows, appends the .#~~~ extension, drops a READ_ME_NOW.txt ransom note, inhibits recovery via tools like vssadmin/wmic/bcdedit/wbadmin/wevtutil, and uses a hybrid cryptographic design. The analyzed Windows variant uses AES-CTR-style bulk file encryption with HMAC-SHA256-style key/IV derivation and incorporates Kyber1024-sized encapsulation material plus active Curve25519/X25519 arithmetic in a fixed 0x744 trailer appended to encrypted files.

Read more
blueteamsecNews
Apr 24, 2026
Kyber Ransomware Double Trouble: Windows and ESXi Attacks Explained - Infosec.Pub

A ransomware strain described as a specialized tool capable of causing a complete operational blackout.

Read more
arstechnica securityNews
Apr 23, 2026
In a first, a ransomware family is confirmed to be quantum-safe - Ars Technica

Ransomware that encrypts files using AES for bulk file encryption and then encrypts the AES key with a claimed post-quantum key encapsulation mechanism; the article suggests its post-quantum branding is primarily a psychological marketing tactic to pressure victims into paying.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching4

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping5

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.