KryBi is a ransomware-as-a-service (RaaS) operation that emerged as a notable ransomware actor by Q2 2026. It was linked to dozens of victims during that quarter and appeared among the more active ransomware groups in contemporary victim-count reporting, indicating a rise from lower visibility into the upper tier of tracked extortion actors. KryBi is associated with ransomware operations and should be understood as part of the broader criminal ransomware ecosystem rather than a state-sponsored intrusion set. High-confidence reporting supports its role as a RaaS service, but the available information does not establish specific victim geographies, preferred industry verticals, technical tradecraft, or sub-group structure. No corroborated aliases beyond KryBi are established in the available data.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.