Krybit Ransomware — Babuk-Derived RaaS Operation Emerges with Double Extortion — Threadlinqs Intelligence
As of 2026-07-13, Krybit Ransomware — Babuk-Derived RaaS Operation Emerges with Double Extortion is a high-severity ransomware threat attributed to KryBit, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 18 indicators of compromise.
Threat ID: TL-2026-1263 · Severity: HIGH · Status: ACTIVE · Category: RANSOMWARE
Attribution: KryBit · FINANCIAL
Krybit is a financially motivated ransomware-as-a-service (RaaS) operation first observed in late March 2026, built on Babuk's leaked 2021 source code. It uses double extortion — exfiltrating 10-250GB
Krybit emerged as a Babuk-derived ransomware-as-a-service operation with earliest confirmed operational activity dated to March 28, 2026 in affiliate panel records, and first underground detection on April 3, 2026. Rather than custom-engineered malware, Krybit's encryptor is built directly on the September 2021 Babuk source code leak — the same leak that spawned at least nine other ransomware families (Play, Mario, Conti POC, REvil/Revix, Cylance, Dataf Locker, Rorschach/BabLock, Lock4, RTM Locker) targeting VMware ESXi. Antivirus engines flag Krybit samples as Babuk variants: Filecoder.Babyk.A (ESET), Babuk!ic (Microsoft), Ransom.Babuk (Combo Cleaner). Inheriting Babuk's architecture, Krybit's encryptor supports Windows, Linux (ELF), VMware ESXi hypervisors, and Network Attached Storage (NAS) devices, using the same elliptic-curve cryptography (ECC) key exchange combined with the Sosemanuk stream cipher characteristic of the original Babuk codebase. Encrypted files are appended with the `.KRYBIT` extension, and a ransom note named `RECOVER-README.txt` is dropped in affected directories. The malware deletes Volume Shadow Copies via `vssadmin.exe delete shadows /all /quiet` to inhibit system recovery (T1490) before encryption (T1486).
Krybit operates a classic RaaS affiliate model with an 80/20 revenue split favoring affiliates. At the time of an April 2026 panel breach, the operation comprised 2 administrators (handles KRYBIT and GREP), 5 affiliates (fsociety, M*A*R*S, D9D938D9AC9, 464D03CA2AF05, 753766EFA0462B), and 20 active victim negotiations. Ransom demands range $40,000-$100,000 per victim, with data staging of 10-250GB prior to encryption. As of the breach, zero ransom payments had been confirmed across five tracked Bitcoin wallets, all showing no transaction history. The affiliate panel exhibited severe operational security failures: plaintext (unhashed, unsalted) storage of both operator/affiliate passwords and victim negotiation communications.
The operation gained wider notoriety through an April 2026 turf war with rival RaaS operator 0APT. On April 12-13, 2026, 0APT breached Krybit's affiliate panel and published the leaked credentials and wallet data on its own leak site, listing Krybit as its first named target and threatening to expose operator identities unless paid. Krybit retaliated within 48 hours (April 14-15, 2026), compromising 0APT's server infrastructure, defacing 0APT's Tor leak site, and publishing 0APT's source code, bash history, nginx logs, and system files. Krybit posted 0APT itself as "victim #1" with the taunt "HACKED BY KRYBIT — Next time, don't play with the big boys." The counter-breach revealed that 0APT's entire data-leak operation had run on an Android phone using AnLinux-Parrot (Parrot OS via Android's Linux compatibility layer), serving content from /sdcard/ through an Nginx-on-port-8080 → PHP 8.2-FPM → Tor hidden service stack, and that the 190+ victims 0APT claimed in January 2026 were entirely fabricated with no actual data exfiltration. Despite the reputational fallout of having its own infrastructure exposed, Krybit has shown no sign of slowing, with new victim claims continuing to appear weekly through June-July 2026, and now maintains 70+ attributed victims and five active Tor leak-site mirrors.
Victimology skews toward Professional Services (21.4%), Technology (17.1%), and Manufacturing (14.3%), with Healthcare, Government, and Education comprising the remainder, spread across 43 countries — led by Germany (10.0%), and Spain and Brazil (7.1% each). No CVE or specific initial-access exploit has been publicly attributed to Krybit; affiliates appear to use varying entry methods consistent with valid-account abuse and remote services (RDP) common to Babuk-lineage affiliates, rather than a single signature vulnerability.
Weaknesses (CWE)
CWE-798, CWE-311, CWE-256
Target sectors: professional-services, technology, manufacturing, health, government administration, education
Target regions: germany, spain, brazil, Global (43 countries)
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 18 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
2 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
RANSOMWARE, HIGH, threat intelligence, cybersecurity, T1078, T1021, T1021.001, T1059, T1547, T1037, T1562, T1021, T1021.001, T1105