Sinobi
0 incidentes
0 paises
0 sectores
apt RU Ultimo: -
Sinobi is a financially motivated ransomware group that emerged in mid-2025, operating as a hybrid Ransomware-as-a-Service (RaaS) model with a small core team and vetted affiliates. Assessed with high confidence to be of Russian or Eastern European origin, the group is widely believed to be a rebrand or direct successor of the Lynx ransomware operation, which itself inherited code from the INC ransomware family following its sale in May 2024. Sinobi distinguishes itself through a disciplined, stealth-focused operational approach, reflected in its name, a stylized reference to 'shinobi' (ninja). The group's primary motivation is purely financial, targeting mid-sized to large organizations with low tolerance for downtime or data leaks, and it consistently employs double extortion tactics to maximize leverage.
Canales, DLS e infraestructura asociada
Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.
Sectores objetivo (SOCRadar)
Food ManufacturingReal EstateHospitalsAccommodationConstructionPublic AdministrationOil & GasWholesale TradeTextile & Fabric ManufacturingRepair&Maintenance