Uptime Hamster: 10d 11h 13mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza kyber

kyber

2 incidentes 1 paises 1 sectores ransomware Ultimo: 2026-06-29
Ver en IntelTracker → APTTrail →
Kyber is a ransomware group first observed in September 2025, distinguishing itself through the use of the Kyber1024 post-quantum encryption standard in its Windows variant to create encryption keys, an approach aimed at rendering future decryption permanently impossible. The group operates under a double extortion model, encrypting victim files and exfiltrating sensitive data, which it threatens to publish on a Tor-based leak site if ransom demands are not met. While the Windows variant genuinely implements Kyber1024, the Linux ESXi version often relies on traditional cryptographic algorithms like RSA-4096 and ChaCha8, despite marketing claims. This group specializes in cross-platform attacks, simultaneously targeting both Windows file servers and VMware ESXi virtualization infrastructure within enterprise environments to achieve widespread operational disruption.

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
Forounknownransomware.anggipradana.comRansomware Group: kyber
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United States (1)

Paises objetivo (SOCRadar)

AustraliaGermanyUnited KingdomUnited States

Sectores atacados

Software (1)

Sectores objetivo (SOCRadar)

Energy & Utilities ManufacturingTransportation&WarehousingInformation ServicesFinanceProfessional&Technical ServicesHealthCare & Social AssistanceOtherPublic AdministrationConstruction of Buildings

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com