Skip to content

Krybit

Krybit is a financially motivated ransomware-as-a-service operation first observed in late March 2026.

Profile source: Mallory opens in a new tab

Krybit

Family profile

Krybit is a financially motivated ransomware-as-a-service operation first observed in late March 2026. The group conducts double-extortion attacks, stealing data before encrypting victim systems and using a Tor-based data leak site to pressure organizations into paying. Public reporting has not established confirmed ties between Krybit and any nation-state or previously known major ransomware brand.

Krybit operates an affiliate model and has been reported to offer an 80/20 revenue split in favor of affiliates. Available reporting indicates support for Windows, Linux, VMware ESXi, and NAS environments, suggesting an intent to target both enterprise IT and virtualized infrastructure. Malware associated with Krybit has been described as Babuk-derived. Documented behaviors include use of Valid Accounts and Remote Services for access, script-based execution, defense evasion, data staging and exfiltration, deletion of shadow copies to inhibit recovery, and encryption for impact. Reporting also links the group to discovery and credential-access activity consistent with mainstream RaaS tradecraft.

Krybitโ€™s targeting appears broad and opportunistic rather than sector-specific. Claimed victims span dozens of countries and multiple industries, with professional services, technology, manufacturing, healthcare, education, financial services, and business services among affected sectors. Germany, Spain, and Brazil have been identified among the more frequently claimed victim geographies. The group has continued to post victims on a near-weekly basis through mid-2026, indicating sustained operational activity despite its relatively recent emergence.

Krybit became unusually visible in April 2026 after rival ransomware group 0APT breached its affiliate panel. Reporting on that exposure indicated Krybit had a small operator and affiliate structure, active victim negotiations, and ransom demands in the tens of thousands of dollars. The leak also suggested weak operational security, including plaintext credential storage. Krybit subsequently retaliated by compromising and defacing 0APT infrastructure and publishing 0APT operational data, making the incident a notable example of conflict between ransomware operators.

Known aliases are limited, and Krybit is primarily tracked under the name Krybit. Public reporting has identified operator aliases within leaked administrative data, but these are not established as separate threat groups or sub-groups. Overall, Krybit is best characterized as an emerging 2026 RaaS actor using conventional affiliate-driven double-extortion tactics, cross-platform ransomware tooling, and opportunistic global targeting.

Operational record

1
YARA rules
1
Ransom notes
5
Leak sites
0 available

Recent claims

MITRE ATT&CK

Krybit in ATT&CK

13 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.