Skip to content

CryptBB

CryptBB is a separately named ransomware operation that has used payloads produced with the leaked LockBit 3.0 builder.

Profile source: MBSD opens in a new tab

CryptBB

Family profile

CryptBB is a separately named ransomware operation that has used payloads produced with the leaked LockBit 3.0 builder. Its LockBit lineage is retained as context rather than treating CryptBB as a LockBit alias.

Operational record

1
YARA rules
1
Leak sites
0 available

Reporting

Research mentioning CryptBB

Aug 20
Register Security

US Bank investigates LockBit's claims as ransomware crims set pay-or-leak deadline

LockBit has listed US Bank on its leak site and claims it stole data from the financial institution, giving the bank 14 days to pay before publishing the material. Reporting on the incident describes it as a ransomware-linked extortion attempt targeting usbank.com, with the gang threatening to leak the allegedly stolen information on September 3 if its demands are not met. US Bank said it is investigating the claim but reported no indication that its internal systems were impacted and no evidence of unauthorized access to its network at the time of its statement. LockBit did not specify what data was allegedly taken, and the claim comes as the group continues operating under LockBit 5.0 after reemerging following a major 2024 law-enforcement disruption and the public identification of alleged operator Dmitry Yuryevich Khoroshev.

Aug 20
Hookphish

Ransomware Group lockbit5 Hits: usbank.com

Aug 12
Hookphish

Ransomware Group clop Hits: HONGHE-TECH.COM

The Clop ransomware operation has repeatedly targeted enterprise networks with intrusions that begin with phishing or exploitation of exposed systems, followed by manual lateral movement, credential theft, and domain-wide deployment. Reporting from ANSSI and AhnLab linked earlier campaigns to TA505, describing attacks in which operators used tools such as Cobalt Strike and Mimikatz, encrypted files with .Clop or .CIop extensions, and disrupted business operations at victims including E-Land Group, Software AG, and reportedly Indiabulls Group. Analysts also observed Clop using signed malware components, targeting Active Directory environments, stopping business-critical services before encryption, and in some cases preserving shadow copies depending on the variant. The group increasingly shifted from encryption-only attacks to double extortion and broader data-leak pressure tactics. Clop operators published stolen files on leak sites, demanded multimillion-dollar payments, contacted victims' customers directly to intensify pressure, and were tied to mass data-theft campaigns exploiting managed file transfer flaws such as CVE-2023-0669 in Fortra GoAnywhere MFT, which was linked to theft from about 130 companies. More recent victim listings attributed to Clop include organizations in the U.S., Canada, Peru, China, Taiwan, and Europe across technology, manufacturing, retail, and other sectors, underscoring the group's continued global focus on enterprise-scale ransomware and data-breach operations.

Aug 12
Hookphish

Ransomware Group clop Hits: 9ALTITUDES.COM

Aug 12
Hookphish

Ransomware Group clop Hits: WATERLANDPE.COM

Aug 12
Hookphish

Ransomware Group clop Hits: NETPOWER.COM

Aug 12
Hookphish

Ransomware Group clop Hits: ALDOGROUP.COM (ALDOSHOES.COM)

Aug 12
Hookphish

Ransomware Group clop Hits: IRCO.COM

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.