Uptime Hamster: 10d 14h 57mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza ciphbit

ciphbit

5 incidentes 1 paises 1 sectores ransomware RU Ultimo: 2026-07-09
Ver en IntelTracker → APTTrail →
CiphBit is a financially motivated ransomware-as-a-service (RaaS) group that commenced operations in April 2023, rapidly evolving to provide tools and services to affiliate attackers. This group primarily targets small to mid-sized businesses and large organizations, particularly those within the manufacturing, healthcare, legal, insurance, telecommunications, and technology sectors, across the UK, Europe, and North America. CiphBit is distinguished by its use of double extortion tactics, including encrypting data and exfiltrating sensitive information to be published on their TOR-based leak site if ransom demands, typically in Bitcoin, are not met. The group leverages anonymization tactics in its infrastructure and communication, making definitive attribution difficult, though it is often associated with Russian-speaking or Eastern European cyber groups.

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
Repositoriounknowngithub.comRansom Notes: ciphbit (1 notes from ThreatLabz)
Tecnicas MITRE
T1078 (Valid Accounts), T1059 (Command and Scripting Interpreter), T1566 (Phishing), T1070 (Indicator Removal on Host), T1486 (Data Encrypted for Impact)
Victimas
4
TTPs unicas
1
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

TTPs observadas

T1566 Phishing

Paises afectados

United States (4)

Paises objetivo (SOCRadar)

United Arab EmiratesAustriaAustraliaBarbadosBelgiumBrazilCanadaSwitzerlandGermanyDominican Republic

Sectores atacados

Software (1)

Sectores objetivo (SOCRadar)

Construction of BuildingsFood ManufacturingOther Information ServicesSoftware PublishersEnterprises & HoldingAccommodationAir TransportationManufacturingConstructionElectrical Equipment, Appliance, and Component Manufacturing

URLs nuevas detectadas en IntelTracker

github.com

Victimas (4)

CiphBit (Unknown / Unmapped Actors)9 Jul 2026
Reference United States
Que es CiphBit es un actor APT (Advanced Persistent Threat) que opera bajo la denominación "Unknown / Unmapped Actors". Este grupo no ha sido asociado…
Ransom Notes: ciphbit (1 notes from ThreatLabz)18 Jun 2026
Report
ciphbit - Ransom NotesEste grupo de ransomware tiene 1 notas de rescate documentadas en el repositorio ThreatLabz/ransomware_notes. Las notas de resca…
Become Affiliate10 Feb 2026
Ransomware United States
Resumen Se ha emitido una alerta de ransomware relacionada con el grupo ciphbit, activo en febrero de 2026. La alerta se centra en actividades de mali…
Affiliate10 Feb 2026
Ransomware United States
Resumen Una alerta de ransomware relacionada con el grupo ciberdelincuental Ciphbit fue publicada el 2026-02-10. Este ataque, asociado a una operación…