Skip to content

CryptBB

CryptBB is a separately named ransomware operation that has used payloads produced with the leaked LockBit 3.0 builder.

Profile source: MBSD opens in a new tab

CryptBB

Family profile

CryptBB is a separately named ransomware operation that has used payloads produced with the leaked LockBit 3.0 builder. Its LockBit lineage is retained as context rather than treating CryptBB as a LockBit alias.

Operational record

1
YARA rules
1
Leak sites
0 available

Reporting

Research mentioning CryptBB

Aug 3
Securelist

Incident response statistics and cases at educational institutions in Brazil | Securelist

Brazilian educational institutions faced a sustained wave of cyber incidents in incident-response cases reviewed from January 2025 through June 2026, with attackers most often gaining access through valid accounts, exploitation of public-facing applications, insider activity, and weak patch management. High-severity cases were dominated by ransomware, particularly DragonForce and LockBit 3, and private institutions were more frequently affected than public ones. Investigators also found that outdated and unpatched systems, including Windows 10 deployments kept past end of support and unpatched Windows Server 2016 hosts, materially increased exposure. Representative intrusions showed attackers relying on common but effective techniques rather than novel tradecraft. One LockBit case involved a custom deployment built from the leaked builder and spread with PsExec, aligning with the well-documented abuse of Windows service execution for lateral movement and payload launch. Another DragonForce intrusion used AnyDesk and log wiping to maintain access and hinder response, while a separate insider case involved a Python keylogger installed on a shared machine to capture credentials. The findings underscore the need for MFA, least privilege, removal of shared accounts, tighter control of remote-access tools, stronger backups, centralized logging, longer EDR retention, and faster patching.

Jul 30
Malware News

Toy Ghouls’ new toy: the GenieLocker ransomware - Malware News - Malware Analysis, News and Indicators

Researchers reported that the financially motivated Toy Ghouls group has deployed a new custom ransomware family, GenieLocker, against organizations in the Russian Federation, with manufacturing firms highlighted among the victims. Active since March 2026, the malware marks a shift away from third-party ransomware such as RedAlert, LockBit, and Babuk to a cross-platform encryptor built for Windows, Linux, and VMware ESXi environments. In a documented intrusion, the attackers reportedly entered through an OpenVPN connection belonging to a trusted external partner by using stolen valid credentials, then expanded access with OpenSSH, SoftPerfect Network Scanner, Mimikatz, PsExec, and PAExec. The Windows variant uses anti-debugging protections, requires a secret launch argument, terminates processes and services, and encrypts data with libsodium implementations of XChaCha20-Poly1305 and Curve25519-XSalsa20-Poly1305, while the Linux/ESXi build includes ESXi-specific behavior such as modifying /etc/vmware/welcome and targeting /vmfs/volumes; researchers said the group typically focuses on encryption rather than data theft or leak-site extortion.

Jul 30
Securelist

New GenieLocker ransomware for Windows, ESXi, and Linux | Securelist

Jul 27
Dark Reading

FBI: Breaking Affiliate Trust Sped Along LockBit's Takedown

International law enforcement agencies said Operation Cronos disrupted LockBit, the ransomware-as-a-service group long described as the world’s most prolific ransomware operation. Authorities seized infrastructure, took control of LockBit’s leak site and platform, exposed affiliates, delivered decryption keys to victims, and publicly revealed that the group sometimes retained stolen victim data and failed to provide working decryptors. According to the FBI, LockBit operated from 2020 to 2024, hit more than 2,500 organizations in at least 120 countries, and collected more than $500 million in ransom payments; several members have since been arrested or charged, while alleged leader Dmitry Yuryevich Khoroshev remains indicted, sanctioned, and at large.

Jul 27
Darktrace

Uncovering a Multi-Stage Ransomware Attack Through Behavioral Detection

Jul 24
Darktrace

When Guardrails Break: Why Securing AI Requires Behavioral Detection and Autonomous Containment

Jul 23
Scworld

Ransomware payments fail to prevent repeat attacks, new data shows | brief | SC Media

Proofpoint survey data shows that paying ransomware demands often fails to end an incident and can expose victims to further extortion. Among affected UK organizations, 58% paid a ransom, and 22% of those payers were targeted again; globally, 54% of victim organizations paid and 37% were extorted a second time. The findings reinforce long-standing warnings that attackers may continue pressuring victims even after receiving payment. The reporting also found that payment does not guarantee recovery: 2% of victims that paid never got their files back, underscoring that criminals may withhold working decryptors or retain stolen data. Coverage cited the LockBit takedown under Operation Cronos as evidence that ransomware operators can keep victim information after payment, while noting that AI is increasingly improving the phishing, credential theft, impersonation, and reconnaissance activity that often precedes ransomware attacks.

Jul 23
Itpro

Companies are still paying ransoms to cyber criminals despite official advice | IT Pro

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.