Uptime Hamster: 10d 11h 13mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza Sinobi

Sinobi

0 incidentes 0 paises 0 sectores apt RU Ultimo: -
Ver en IntelTracker → APTTrail →
Sinobi is a financially motivated ransomware group that emerged in mid-2025, operating as a hybrid Ransomware-as-a-Service (RaaS) model with a small core team and vetted affiliates. Assessed with high confidence to be of Russian or Eastern European origin, the group is widely believed to be a rebrand or direct successor of the Lynx ransomware operation, which itself inherited code from the INC ransomware family following its sale in May 2024. Sinobi distinguishes itself through a disciplined, stealth-focused operational approach, reflected in its name, a stylized reference to 'shinobi' (ninja). The group's primary motivation is purely financial, targeting mid-sized to large organizations with low tolerance for downtime or data leaks, and it consistently employs double extortion tactics to maximize leverage.

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / leak siteunknownransomware.anggipradana.comRansomware Group: sinobi
Tecnicas MITRE
T1021.002 - SMB/Windows Admin Shares, T1569.002 - Service Execution, T1083 - File and Directory Discovery, T1567 - Exfiltration Over Web Service, T1489 - Service Stop, T1078 - Valid Accounts
CVEs relacionadas
CVE-2025-5777, CVE-2024-57727, CVE-2023-48788, CVE-2023-3519
Tipo
apt
Pais origen
RU
Motivacion
-
Impacto
77
Actualizado
Tue, 03 Fe

Sectores objetivo (SOCRadar)

Food ManufacturingReal EstateHospitalsAccommodationConstructionPublic AdministrationOil & GasWholesale TradeTextile & Fabric ManufacturingRepair&Maintenance