DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 06:03:37ZSOURCES: 14CRITICAL: 15
⚠ ACTIVE ALERTS
SYLVANITE CRITICAL — SYLVANITE is a newly named Dragos-tracked threat group identified as a dedicated… /// @MsftSecIntel CRITICAL — We are tracking TeamPCP (UNC6780) activity following the GitHub internal repository… /// @GossiTheDog CRITICAL — The GitHub / TeamPCP breach is now being monetized on BreachForums. Listing is up — $95k… /// @struppigel CRITICAL — SUPPLY CHAIN ALERT: Laravel-Lang PHP packages backdoored May 22-23 via hijacked GitHub… /// @MalwareHunterTeam CRITICAL — Seeing fresh DebugElevator stealer log batches already appearing for sale on Exploit.in —…
15Critical Threats
8Active CVEs
0IOCs Tracked
0New Advisories
TLP:WHITETHREAT ACTOR DOSSIER // KRYBIT-RAASFIRST SEEN: MAR 2026

KryBit

ALSO KNOWN AS: KRYBIT
FROM:DMZ INTELLIGENCE DESK
ORIGIN:Unknown
ATTRIBUTION:ORGANIZED CRIME
STATUS:ACTIVE
FIRST OBSERVED:MAR 2026
TECHNICALRESOURCESPERSISTENCESTEALTHIMPACT
TECHNICAL42/100
RESOURCES42/100
PERSISTENCE45/100
STEALTH37/100
IMPACT51/100

KryBit is an emerging RaaS operation that launched in late March 2026, offering affiliates an aggressive 80/20 revenue split with cross-platform ransomware builders for Windows, Linux, ESXi, and NAS devices. The group posted 10 legitimate victims within its first two weeks and engaged in a high-profile ransomware turf war with rival group 0APT in April 2026, in which KryBit successfully hacked back, defaced 0APT's infrastructure, and exposed its full operational dataset — revealing that 0APT's 190+ claimed victims were entirely fabricated. Despite active affiliate operations and staged victim data (10–250GB per victim, ransom demands $40K–$100K), KryBit had collected zero ransom payments as of mid-April 2026 per leaked wallet data. The group employs structured double-extortion with shadow copy deletion and TOR-based leak infrastructure.

Financial extortion via RaaS affiliate model targeting enterprises globally

Double extortion (encryption + data leak), shadow copy deletion (vssadmin delete shadows /all /quiet), process injection, defense evasion via obfuscation and registry key manipulation, credential access, cross-platform builder (Windows/Linux/ESXi/NAS), TOR-based DLS, T1490 inhibit system recovery, T1486 data encrypted for impact, T1070 indicator removal

MANUFACTURING
ENERGY
EDUCATION
TELECOMMUNICATIONS
REAL ESTATE
CONSUMER GOODS
PROFESSIONAL SERVICES

TOR hidden services (.onion DLS); six .onion domains exposed in April 2026 0APT hack; Tox communication handles for operators and affiliates; RECOVER-README.txt ransom notes; .KRYBIT file extension; YARA rules published at ransomware.live (date 2026-05-04); no confirmed infostealer component

FILE DATE: MAR 2026
KryBit RaaS Launch
KryBit launched its RaaS platform with 80/20 affiliate model and multi-platform builders, posting 10 confirmed victims within two weeks across consumer, professional services, energy, and telecom sectors spanning Japan, Austria, Brazil, Spain, Hong Kong, and the US.
FILE DATE: APR 2026
0APT Ransomware Turf War
After rival group 0APT leaked KryBit's affiliate panel and threatened to █████████████████████ hacked back within 48 hours, defacing 0APT's site and publishing its complete operational database including PHP source, bash history, and nginx logs — proving 0APT's 190+ victim claims were entirely fabricated.
SHARE BRIEF:✕ Post on Xin Share on LinkedIn