cry0 is a ransomware threat actor active in 2026 and associated with extortion activity, victim posting, and participation in underground ransomware ecosystems. The group has been linked to a ransomware attack against a U.S.-based retail and e-commerce organization and has been referenced as engaging on the T1erOne underground forum, a platform that permits ransomware-related activity and affiliate-oriented promotion. cry0 has also reportedly sponsored a technical article contest on an underground forum focused on exploit development, offensive tradecraft, vulnerability research, and AV/EDR bypass techniques, indicating interest in cultivating or incentivizing offensive capability development within criminal communities. A notable operational characteristic attributed to cry0 is the use of the Internet Computer Protocol blockchain for extortion negotiations. This reflects experimentation with decentralized infrastructure in support of ransomware operations. Available information supports classifying cry0 as a financially motivated ransomware actor engaged in extortion, but does not provide high-confidence detail on its full intrusion lifecycle, malware deployment methods, victimology breadth, or organizational structure beyond its presence in ransomware-focused underground spaces.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a ransomware attack resulting in a data breach against Hope’s Windows.
Ransomware brand mentioned as a comparison for narrower blockchain use in extortion negotiations.
Reportedly sponsoring a dark web article contest on the TierOne forum focused on vulnerability exploitation and offensive technical research topics.
Referenced as engaging on the gated T1erOne forum in the post-RAMP disruption period, suggesting exploratory or early-stage affiliate/recruitment activity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.