Tox
1 total54E9450799AFBBA90992E3C40F552C8C05D5765144396C6A1A622FD9DABD01101F9DC0CF90F4
cry0 is a ransomware threat actor operating in the cybercriminal ecosystem and associated with extortion activity, underground forum engagement, and sponsorship of offensive security knowledge-sharing initiatives.
Profile source: Mallory opens in a new tabCry0
cry0 is a ransomware threat actor operating in the cybercriminal ecosystem and associated with extortion activity, underground forum engagement, and sponsorship of offensive security knowledge-sharing initiatives. Public reporting places the group in ransomware-related communities during 2026, including references to its presence on the T1erOne forum after the disruption of the RAMP forum, indicating participation in the broader post-RAMP migration and fragmentation of ransomware coordination spaces.
The group has been linked to use of blockchain-based infrastructure in its extortion workflow, specifically the Internet Computer Protocol (ICP) blockchain for negotiation-related activity. This reflects experimentation with decentralized services to support ransomware operations and aligns with a broader trend among financially motivated actors adopting blockchain-backed mechanisms to complicate disruption and monitoring.
cry0 has also been associated with sponsorship of a dark web technical article contest focused on vulnerability exploitation and offensive tradecraft. Topics promoted in that contest included remote code execution, command injection, insecure deserialization, firmware exploitation, zero-day research, AI-assisted vulnerability discovery, and AV/EDR bypass techniques. This association suggests an interest in cultivating or incentivizing exploit-development expertise within underground communities, potentially to support affiliate recruitment, capability development, or ecosystem influence.
Available information supports characterizing cry0 as a financially motivated ransomware actor rather than attributing it to a nation-state. Reporting currently provides only limited corroborated detail on its victimology, malware lineage, intrusion chain, or internal subgroup structure, and no high-confidence aliases beyond the stylized name cry0 are presently established.
54E9450799AFBBA90992E3C40F552C8C05D5765144396C6A1A622FD9DABD01101F9DC0CF90F445.227.253.59:3111Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.