Back to Intelligence

KRYBIT Ransomware Gang: 6 New Leak-Site Claims Posted — Sector Targeting Analysis & Detection Rules

SA
Security Arsenal Team
October 2, 2026
13 min read

Classification: TLP:CLEAR | Publication Date: 2026-10-03 | Source: ransomware.live leak-site monitoring (single-source for some listings — see Sourcing & Verification) | Nature of data: Unverified threat-actor claims

KRYBIT Ransomware Gang: 6 New Leak-Site Claims Posted — Sector Targeting Analysis & Detection Rules

Executive Summary

Security Arsenal's dark web monitoring has observed a burst of activity on the KRYBIT ransomware gang's Tor-based leak site. Between 2026-10-01 and 2026-10-02, the group listed six organizations it claims to have compromised, spanning Czechia, India, France, and the United States across retail/e-commerce, education, technology, and manufacturing sectors.

These postings are claims made by a criminal group and are not confirmed breaches. However, leak-site activity of this tempo is a reliable leading indicator of an active campaign, and organizations in the affected sectors and geographies — as well as any organization running the exposed edge technologies discussed below — should treat this bulletin as a trigger for immediate detection review and hardening.

Five of the six listings were independently observed by a second leak-site crawler, confirming the postings exist on KRYBIT's site. One listing appears on a single source only. Details in the Sourcing & Verification section below.

Sourcing & Verification

  • Corroboration status: 5 of 6 listings in this bulletin were independently observed by a second leak-site crawler (multi-source). 1 listing — EURODITEL/RESOTELECOM — appears on ransomware.live only, with no second-crawler confirmation that the posting exists. Single-source items carry elevated risk of parsing error or site fluctuation and are flagged accordingly.
  • What a listing means: Inclusion in this bulletin reflects the threat actor's claim only. It is not confirmation that any named organization suffered a breach, intrusion, or data theft. No corroboration tier in leak-site monitoring confirms a breach — only the organization itself or its regulator can do that.
  • Disputes and denials: A named organization may dispute or deny the listing. A denial is likewise not proof the claim is false — disclosure obligations vary by jurisdiction and sector, and not every incident is reportable, so neither silence nor denial settles the question. We report claims as claims, full stop.
  • Corrections: Security Arsenal will publish corrections promptly. We welcome contact from any named organization at security@securityarsenal.com.

Threat Actor Profile — KRYBIT

KRYBIT is an emerging ransomware operation that surfaced on the ransomware.live tracking index in 2025 and has maintained a low-to-moderate but persistent leak-site tempo. Our assessment of its operational profile, based on observed postings and community reporting:

  • Aliases: No widely documented aliases; some trackers note overlapping infrastructure and negotiation-page templates with defunct mid-tier RaaS programs, suggesting possible affiliate re-branding rather than a wholly new crew.
  • Operating model: Assessed as a small closed group or invite-only RaaS with limited affiliate recruitment. Posting volume (6 victims across two days, then quiet periods) is consistent with a lean operator team rather than a high-volume affiliate program.
  • Ransom demands: Observed demands trend toward the mid five-figure to low seven-figure USD range, sized to victim revenue — consistent with the small-to-mid-market organizations it lists.
  • Initial access methods: Community reporting and incident telemetry associate KRYBIT intrusions with:
    • Exploitation of internet-facing VPN and firewall appliances (unpatched edge devices).
    • RDP brute force / password spraying against exposed remote access.
    • Phishing with macro-enabled documents delivering second-stage loaders.
    • Opportunistic abuse of known exploited vulnerabilities (see CVE section below).
  • Extortion model: Double extortion — data exfiltration before encryption, with leak-site publication used as leverage. The current postings are the extortion phase of that playbook.
  • Dwell time: Estimated 4–10 days from initial access to detonation based on reporting on comparable mid-tier groups; exfiltration staging typically begins 48–72 hours before encryption.

Current Campaign Analysis

Sectors Targeted (per leak-site listings)

KRYBIT's current batch of claimed victims spans:

  • Retail & E-Commerce — www.raajratna.com (IN)
  • Education — sai.org.in (IN)
  • Technology / Telecommunications — EURODITEL/RESOTELECOM (FR) [single-source listing]
  • Manufacturing — DISK PRECISION GROUP - diskprecision.com (US)
  • Other / Public-facing services — www.pierrefeu.fr (FR)
  • Unclassified — www.kres.cz (CZ)

Geographic Concentration

Four countries across two clusters: a South Asia / India cluster (2 of 6 listings) and a European cluster (CZ, 2× FR), plus one US manufacturing organization. This split is consistent with opportunistic edge-device exploitation rather than deliberate country selection — exposed perimeter appliances don't respect borders.

Victim Profile

The listed organizations appear to be small-to-mid-market entities — regional manufacturers, educational institutions, local telecom/IT providers, and niche e-commerce operations. Estimated revenue range for this victim profile is roughly $1M–$100M annually. This is the classic mid-tier ransomware hunting ground: organizations large enough to pay, small enough to lack 24/7 SOC coverage and mature backup discipline.

Posting Frequency & Escalation

Two consecutive posting days (2026-10-01, 2026-10-02) with six total listings suggests either a batch of intrusions matured simultaneously or a deliberate publicity push. Watch for follow-on postings in the next 7–14 days; a second wave would indicate the campaign is ongoing rather than a one-time dump of completed intrusions.

CVE Exposure — Sector-Level Hypothesis (Not Victim Attribution)

We have no evidence linking any specific CVE to any specific named organization in this campaign. However, KRYBIT's known tradecraft — edge-device exploitation and opportunistic KEV abuse — makes the following actively exploited vulnerabilities (all confirmed ransomware-associated per CISA KEV) priority patch items for defenders:

  • CVE-2026-59310 — Broadcom VMware vCenter path traversal (KEV 2026-08-18). Hypervisor management compromise is a force multiplier for mass encryption.
  • CVE-2026-20316 — Cisco Secure Firewall Management Center hard-coded password (KEV 2026-07-29). Direct edge-device takeover — matches KRYBIT's assessed VPN/firewall initial access pattern.
  • CVE-2026-50751 — Check Point Security Gateway improper authentication in IKEv1 (KEV 2026-06-08). VPN gateway compromise — again matching the edge-access profile.
  • CVE-2026-63077 — JetBrains TeamCity deserialization (KEV 2026-08-05). CI/CD compromise enables supply-chain-style lateral spread and code-signing abuse.
  • CVE-2026-48027 — Nx Console embedded malicious code (KEV 2026-05-27). Developer-toolchain supply chain exposure.

Defender takeaway: If you run VMware vCenter, Cisco FMC, or Check Point gateways and have not patched these, assume adversaries are probing for them today — regardless of whether KRYBIT specifically is.

Detection Engineering

The following detections target KRYBIT's assessed playbook: edge/VPN initial access, phishing macro execution, RDP brute force, PsExec/WMI lateral movement, and pre-encryption data staging.

YAML
---
title: KRYBIT - Phishing Macro Spawning Script Interpreter
id: 9f1a2b3c-kryb-0001-a001-000000000001
status: experimental
description: Detects Office applications spawning script interpreters or LOLBins, consistent with KRYBIT macro-based initial access
author: Security Arsenal Threat Intelligence
date: 2026/10/03
references:
  - https://securityarsenal.com/darkside
logsource:
  category: process_creation
  product: windows
detection:
  selection_parent:
    ParentImage|endswith:
      - '\winword.exe'
      - '\excel.exe'
      - '\powerpnt.exe'
      - '\outlook.exe'
  selection_child:
    Image|endswith:
      - '\powershell.exe'
      - '\pwsh.exe'
      - '\wscript.exe'
      - '\cscript.exe'
      - '\mshta.exe'
      - '\rundll32.exe'
      - '\cmd.exe'
      - '\certutil.exe'
  condition: selection_parent and selection_child
falsepositives:
  - Rare legitimate Office automation; baseline per environment
level: high
tags:
  - attack.initial_access
  - attack.t1566.001
  - attack.t1059
---
title: KRYBIT - RDP Brute Force Followed by Successful Logon
id: 9f1a2b3c-kryb-0002-a001-000000000002
status: experimental
description: Detects burst of failed RDP logons (4625, logon type 10/3) from a single source followed by a successful interactive/remote logon (4624), consistent with KRYBIT RDP password-spraying tradecraft
author: Security Arsenal Threat Intelligence
date: 2026/10/03
references:
  - https://securityarsenal.com/darkside
logsource:
  product: windows
  service: security
detection:
  selection_failed:
    EventID: 4625
    LogonType:
      - 3
      - 10
  selection_success:
    EventID: 4624
    LogonType:
      - 3
      - 10
  condition: selection_failed | count() by SourceIp > 10
falsepositives:
  - Misconfigured service accounts; network scanners
level: high
tags:
  - attack.credential_access
  - attack.t1110
  - attack.t1021.001
---
title: KRYBIT - Pre-Encryption Staging - Shadow Copy Deletion and Admin Share Tool Drop
id: 9f1a2b3c-kryb-0003-a001-000000000003
status: experimental
description: Detects vssadmin/wmic/bcdedit shadow copy deletion or file drops to ADMIN$ shares, consistent with KRYBIT pre-encryption anti-recovery and PsExec-style lateral movement
author: Security Arsenal Threat Intelligence
date: 2026/10/03
references:
  - https://securityarsenal.com/darkside
logsource:
  category: process_creation
  product: windows
detection:
  selection_vss:
    CommandLine|contains:
      - 'vssadmin delete shadows'
      - 'vssadmin Delete Shadows'
      - 'wmic shadowcopy delete'
      - 'bcdedit'
      - 'wbadmin delete catalog'
      - 'diskshadow'
  selection_psexec:
    Image|endswith:
      - '\psexec.exe'
      - '\psexesvc.exe'
      - '\paexec.exe'
      - '\csexec.exe'
  condition: 1 of selection_*
falsepositives:
  - Legitimate backup maintenance windows; remote administration tooling. Correlate with new service installs (EventID 7045).
level: critical
tags:
  - attack.impact
  - attack.t1490
  - attack.t1569.002
  - attack.lateral_movement

The following KQL query hunts for pre-ransomware staging behavior in Microsoft Sentinel: a host that shows new admin-share file writes or remote service creation, followed by mass file renames or shadow copy deletion within a short window — KRYBIT's assessed pre-detonation sequence.

KQL — Microsoft Sentinel / Defender
// KRYBIT pre-encryption staging hunt: lateral tool drop -> shadow copy tampering -> mass file modification
let lookback = 7d;
let suspiciousProcs = dynamic(["psexec.exe","psexesvc.exe","paexec.exe","csexec.exe","vssadmin.exe","wbadmin.exe","bcdedit.exe","diskshadow.exe"]);
let StageHosts =
    DeviceProcessEvents
    | where TimeGenerated > ago(lookback)
    | where FileName in~ (suspiciousProcs)
       or ProcessCommandLine has_any ("delete shadows","shadowcopy delete","delete catalog","recoveryenabled no")
    | summarize FirstSeen=min(TimeGenerated), Commands=make_set(ProcessCommandLine, 20) by DeviceName, bin(TimeGenerated, 1h);
let MassRename =
    DeviceFileEvents
    | where TimeGenerated > ago(lookback)
    | where ActionType in ("FileRenamed","FileModified")
    | summarize RenameCount=count(), Extensions=make_set(tostring(split(FolderPath, ".")[-1]), 25)
        by DeviceName, bin(TimeGenerated, 1h)
    | where RenameCount > 200;  // tune threshold per environment baseline
StageHosts
| join kind=inner MassRename on DeviceName, TimeGenerated
| project DeviceName, StagingWindow=TimeGenerated, FirstSeen, RenameCount, Commands, Extensions
| order by FirstSeen asc;

The following PowerShell script is a rapid-response triage helper for the assets KRYBIT prioritizes: it checks for internet-exposed RDP, enumerates scheduled tasks created in the last 7 days, lists recently installed services, and reports Volume Shadow Copy health. Run it on edge-adjacent servers and any host flagged by the detections above.

PowerShell
# Security Arsenal - KRYBIT Rapid Triage Script
# Run elevated. Outputs to C:\Temp\krybit_triage_<hostname>_<date>.txt
$out = "C:\Temp\krybit_triage_$($env:COMPUTERNAME)_$(Get-Date -Format 'yyyyMMdd_HHmm').txt"
New-Item -Path C:\Temp -ItemType Directory -Force | Out-Null

"=== KRYBIT Rapid Triage - $(Get-Date) - $env:COMPUTERNAME ===" | Out-File $out

# 1) RDP exposure check
"`n[1] RDP Listener Status" | Out-File $out -Append
$rdp = Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server' -Name fDenyTSConnections -ErrorAction SilentlyContinue
$port = (Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -Name PortNumber -ErrorAction SilentlyContinue).PortNumber
"RDP Enabled: $(if($rdp.fDenyTSConnections -eq 0){'YES - REVIEW EXPOSURE'}else{'Disabled'}) | Port: $port" | Out-File $out -Append
Get-NetFirewallRule -DisplayGroup 'Remote Desktop' -ErrorAction SilentlyContinue |
  Where-Object {$_.Enabled -eq 'True'} | Select-Object DisplayName,Profile,Action | Out-File $out -Append

# 2) Scheduled tasks created in last 7 days
"`n[2] Scheduled Tasks Created/Modified Last 7 Days" | Out-File $out -Append
Get-ScheduledTask | ForEach-Object {
  $info = $_ | Get-ScheduledTaskInfo -ErrorAction SilentlyContinue
  [PSCustomObject]@{Name=$_.TaskName; Path=$_.TaskPath; State=$_.State; LastRun=$info.LastRunTime}
} | Where-Object {$_.Path -notlike '\Microsoft*'} | Format-Table -AutoSize | Out-File $out -Append
Get-WinEvent -FilterHashtable @{LogName='Microsoft-Windows-TaskScheduler/Operational'; Id=106; StartTime=(Get-Date).AddDays(-7)} -ErrorAction SilentlyContinue |
  Select-Object TimeCreated,Message | Format-List | Out-File $out -Append

# 3) Services installed in last 7 days (PsExec-style lateral movement indicator)
"`n[3] New Service Installs (Event 7045) Last 7 Days" | Out-File $out -Append
Get-WinEvent -FilterHashtable @{LogName='System'; Id=7045; StartTime=(Get-Date).AddDays(-7)} -ErrorAction SilentlyContinue |
  Select-Object TimeCreated,Message | Format-List | Out-File $out -Append

# 4) Volume Shadow Copy health
"`n[4] Volume Shadow Copies" | Out-File $out -Append
$shadows = Get-CimInstance Win32_ShadowCopy -ErrorAction SilentlyContinue
if ($shadows) { $shadows | Select-Object VolumeName,InstallDate | Format-Table -AutoSize | Out-File $out -Append }
else { "NO SHADOW COPIES FOUND - potential anti-recovery activity if recently deleted (review Event 7036/524)" | Out-File $out -Append }
vssadmin list shadows 2>&1 | Out-File $out -Append

# 5) Recent failed logons (password spray / brute force)
"`n[5] Failed Logons (4625) Last 24h by Source" | Out-File $out -Append
Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4625; StartTime=(Get-Date).AddDays(-1)} -ErrorAction SilentlyContinue |
  Group-Object {$_.Properties[19].Value} | Sort-Object Count -Descending | Select-Object -First 15 Count,Name |
  Format-Table -AutoSize | Out-File $out -Append

"`nTriage complete: $out"

Incident Response Priorities

T-Minus Detection Checklist — Before Encryption Fires

KRYBIT's assessed 48–72 hour staging window gives defenders a real opportunity. Hunt for:

  1. New remote access artifacts: unexpected VPN logons from unusual geographies, RDP sessions from non-standard sources, 7045 service installs matching PsExec clones.
  2. Recon tooling: net group "Domain Admins", nltest /dclist:, BloodHound/SharpHound collection files (*_computers.json, *_users.json), Advanced IP Scanner processes.
  3. Credential theft: LSASS access by non-system processes (Event 10 with GrantedAccess 0x1010), NTDS.dit staging via ntdsutil or Volume Shadow abuse.
  4. Exfiltration staging: large archives (7z/RAR) in user temp or program data directories, outbound transfers >2GB to unfamiliar destinations, Rclone/MEGAsync/FileZilla binaries on servers.
  5. Anti-recovery pre-positioning: shadow copy deletion commands, backup agent tampering or uninstalls, bcdedit recovery disablement.

Assets Historically Prioritized for Exfiltration

Based on the double-extortion playbook for mid-tier groups like KRYBIT, expect targeting of:

  • Finance and HR data stores (payroll, banking details, PII) — highest extortion leverage.
  • File servers and NAS devices hosting client/project data.
  • Email archives of executive accounts (for negotiation pressure and follow-on BEC).
  • Backup catalogs and credentials — to degrade recovery before detonation.

Containment Actions — Ordered by Urgency

  1. Isolate edge exposure: disable or ACL-restrict RDP/VPN from the internet; force password resets on any account with failed-logon anomalies.
  2. Kill active sessions: revoke VPN sessions, invalidate tokens, disable suspicious accounts — speed beats completeness here.
  3. Segment: VLAN-isolate hosts showing staging indicators; block SMB between workstation segments.
  4. Protect backups: take backup infrastructure offline or immutable-locked; verify shadow copies exist on critical servers before they are deleted, not after.
  5. Capture volatile evidence: memory and triage collections on suspected staging hosts before remediation wipes artifacts.
  6. Engage IR: if staging indicators confirm, activate your retainer — the 48–72 hour window closes fast.

Hardening Recommendations

Immediate (24 hours)

  • Patch the KEV edge stack: CVE-2026-20316 (Cisco FMC), CVE-2026-50751 (Check Point IKEv1), CVE-2026-59310 (vCenter). These are confirmed ransomware-exploited; treat as emergency change.
  • Disable internet-facing RDP entirely; require VPN + MFA for all remote access. Audit current VPN concentrator firmware.
  • Enforce phishing-resistant MFA (FIDO2/hardware keys) on VPN, email, and all admin interfaces.
  • Block Office macros from the internet via Mark-of-the-Web policy; alert on Office spawning child processes (Sigma rule 1 above).
  • Deploy the detections in this bulletin to your SIEM and run the triage script on any internet-adjacent Windows server.
  • Verify backup integrity and immutability — confirm at least one offline/immutable copy and test a restore of one critical system.

Short-Term (2 weeks)

  • Network segmentation: isolate backup infrastructure, restrict workstation-to-workstation SMB/RPC, and put domain controllers and hypervisor management planes (vCenter) on dedicated, jump-host-only segments.
  • Deploy EDR with tamper protection across servers and workstations; enable blocking-mode for credential theft and shadow copy deletion behaviors.
  • Deception: deploy honeypot credentials, canary file shares, and decoy RDP listeners — mid-tier groups like KRYBIT trip these reliably during recon.
  • Email security uplift: attachment sandboxing, DMARC enforcement, and banner tagging for external mail.
  • Outbound egress filtering: alert on large transfers and on consumer exfil tooling (Rclone, MEGA, FileZilla) from server segments.
  • Tabletop the extortion scenario: legal, comms, and leadership should rehearse a leak-site listing response before you're reading your own name on one.

Related Resources

Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.