# KryBit

> As of 2026-07-13, KryBit is a threat actor tracked by Threadlinqs Intelligence across 2 threats spanning ransomware. Also known as KryBit RaaS, KryBit Ransomware. ATT&CK coverage spans 46 techniques across 15 tactics in 2 of 2 tracked threats. Most-observed techniques: T1021.001 (Remote Desktop Protocol), T1041 (Exfiltration Over C2 Channel), T1071 (Application Layer Protocol).

- **Tracked threats:** 2
- **Categories:** RANSOMWARE
- **Also known as:** KryBit RaaS, KryBit Ransomware
- **As of:** 2026-07-13

## ATT&CK techniques observed

46 techniques observed across 2 of 2 tracked threats. Tactics: Execution (5), Impact (5), Command and Control (4), Discovery (4), Initial Access (4), Persistence (4).

- [T1021.001](https://intel.threadlinqs.com/technique/T1021.001) Remote Desktop Protocol — Lateral Movement — observed in 2 of 2 tracked threats
- [T1041](https://intel.threadlinqs.com/technique/T1041) Exfiltration Over C2 Channel — Exfiltration — observed in 2 of 2 tracked threats
- [T1071](https://intel.threadlinqs.com/technique/T1071) Application Layer Protocol — Command and Control — observed in 2 of 2 tracked threats
- [T1078](https://intel.threadlinqs.com/technique/T1078) Valid Accounts — Initial Access — observed in 2 of 2 tracked threats
- [T1486](https://intel.threadlinqs.com/technique/T1486) Data Encrypted for Impact — Impact — observed in 2 of 2 tracked threats
- [T1490](https://intel.threadlinqs.com/technique/T1490) Inhibit System Recovery — Impact — observed in 2 of 2 tracked threats
- [T1567](https://intel.threadlinqs.com/technique/T1567) Exfiltration Over Web Service — Exfiltration — observed in 2 of 2 tracked threats
- [T1573](https://intel.threadlinqs.com/technique/T1573) Encrypted Channel — Command and Control — observed in 2 of 2 tracked threats
- [T1685](https://intel.threadlinqs.com/technique/T1685) Disable or Modify Tools — Defense Impairment — observed in 2 of 2 tracked threats
- [T1003.001](https://intel.threadlinqs.com/technique/T1003.001) LSASS Memory — Credential Access — observed in 1 of 2 tracked threats
- [T1005](https://intel.threadlinqs.com/technique/T1005) Data from Local System — Collection — observed in 1 of 2 tracked threats
- [T1018](https://intel.threadlinqs.com/technique/T1018) Remote System Discovery — Discovery — observed in 1 of 2 tracked threats
- [T1021](https://intel.threadlinqs.com/technique/T1021) Remote Services — Lateral Movement — observed in 1 of 2 tracked threats
- [T1021.004](https://intel.threadlinqs.com/technique/T1021.004) SSH — Lateral Movement — observed in 1 of 2 tracked threats
- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 1 of 2 tracked threats

## Tracked threats

- [Krybit Ransomware — Babuk-Derived RaaS Operation Emerges with Double Extortion](https://intel.threadlinqs.com/threat/TL-2026-1263) — HIGH
- [KryBit Ransomware-as-a-Service Strikes Back — Breaches 0APT Infrastructure Amid Faux-Ransomware Feud (May 2026)](https://intel.threadlinqs.com/threat/TL-2026-0508) — HIGH

## Related CVEs

1 CVE referenced by tracked KryBit activity.

- [CVE-2026-41940](https://intel.threadlinqs.com/cve/CVE-2026-41940)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/KryBit
