Uptime Hamster: 21d 18h 4mDeploy: 3 Aug 2026 06:56Updated: 2026-07-21
Logo del actor de amenaza kyber

kyber

2 incidentes 1 paises 1 sectores threat-actor Ultimo: 2026-06-29
Ver en IntelTracker → APTTrail →
Kyber is a ransomware group first observed in September 2025, distinguishing itself through the use of the Kyber1024 post-quantum encryption standard in its Windows variant to create encryption keys, an approach aimed at rendering future decryption permanently impossible. The group operates under a double extortion model, encrypting victim files and exfiltrating sensitive data, which it threatens to publish on a Tor-based leak site if ransom demands are not met. While the Windows variant genuinely implements Kyber1024, the Linux ESXi version often relies on traditional cryptographic algorithms like RSA-4096 and ChaCha8, despite marketing claims. This group specializes in cross-platform attacks, simultaneously targeting both Windows file servers and VMware ESXi virtualization infrastructure within enterprise environments to achieve widespread operational disruption.

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
Forounknownransomware.anggipradana.comRansomware Group: kyber
DLS / oniononlinekyblogtz6k3jtxnjjvluee5ec4g3zcnvyvbgsnq5thumphmqidkt7xid.onionCTI.FYI
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United States (1)

Paises objetivo (OSINT)

AustraliaGermanyUnited KingdomUnited States

Sectores atacados

Software (1)

Sectores objetivo (OSINT)

Energy & Utilities ManufacturingTransportation&WarehousingInformation ServicesFinanceProfessional&Technical ServicesHealthCare & Social AssistanceOtherPublic AdministrationConstruction of Buildings

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com