Ransomware group profile · #291 by claimed victims
Cry0 ransomware
Cry0 is a ransomware-as-a-service operation that recruits affiliates via underground forums, using a Rust-written payload with blockchain-based (Internet Computer Protocol) negotiation infrastructure to resist law enforcement takedowns and offering affiliates a 90/10 revenue split.
Victimology
Who Cry0 claims to have breached, from 2 leak-site posts recorded by VULONE.
Claims per month last 12 months
Top sectors
Top countries
Latest claimed victims 2 most recent
| Victim | Sector | Country | Claimed |
|---|---|---|---|
| Hope's Windows | Retail & E-Commerce | US | 6 Aug 2026 |
| dinisrl.it dinisrl.it | Transportation | IT | 6 Jul 2026 |
All 2 Cry0 victims, searchable
Full victim list with claim posts, domains, timing and exports, plus the negotiation chats and leak-site screenshots VULONE archives for this crew.
Tactics, techniques and procedures
ATT&CK technique mapping for Cry0 is in progress. Victimology, infrastructure status and leak-site tracking are live above.
Indicators, detections and the full playbook
Hashes, C2 addresses, onion services, Sigma and YARA detections per technique, and the negotiation transcripts are available to signed-in analysts.
Frequently asked
Is Cry0 ransomware still active?
How many victims has Cry0 claimed?
Which industries does Cry0 target?
Which countries are most affected by Cry0?
Where does VULONE get Cry0 victim data?
Other ransomware groups
Victim claims are collected from leak sites and enrichment partners (ransomware.live, RansomLook) and represent the group's own assertions, not confirmed breaches. Profile last updated 16 September 2026. Questions or corrections: [email protected].