Uptime Hamster: 10d 6h 2mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza weyhro

weyhro

2 incidentes 2 paises 1 sectores ransomware RU Ultimo: 2026-06-29
Ver en IntelTracker → APTTrail →
Weyhro is a financially motivated data extortion group that emerged in late 2024, rapidly gaining prominence on underground forums by December of that year and launching its dedicated Tor-based leak site by March 2025. While some reports characterize Weyhro primarily as a data exfiltration group operating without file encryption, others indicate they engage in double extortion, which includes both data theft and encryption. A distinguishing characteristic of this threat actor is the alleged shift of its operator, as of December 2025, towards selling a sophisticated command-and-control (C2) toolkit called Weyhro C2, marketed for advanced penetration testing and stealth operations, signaling a potential expansion of their criminal enterprise beyond direct ransomware attacks to enabling other cybercriminals. The group's activities include a notable restriction on its toolkit from operating within Commonwealth of Independent States (CIS) systems, a common tactic among Russian or Eastern Eu

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / leak siteunknownransomware.anggipradana.comRansomware Group: weyhro
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United States (1) Canada (1)

Paises objetivo (SOCRadar)

AustraliaBarbadosCanadaGermanyUnited KingdomIndiaItalyComorosSomaliaThailand

Sectores atacados

Manufacturing (1)

Sectores objetivo (SOCRadar)

Construction of BuildingsOther Information ServicesSoftware PublishersReal EstateEnterprises & HoldingManufacturingConstructionPublic AdministrationAdministrative &Waste Management Educational Services

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com