Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Enjoying ransomware.live? Help us keep tracking ransomware gangs and shipping new features. Support us

Cry0

| Active | RaaS

Cry0 is a ransomware-as-a-service operation that recruits affiliates via underground forums, using a Rust-written payload with blockchain-based (Internet Computer Protocol) negotiation infrastructure to resist law enforcement takedowns and offering affiliates a 90/10 revenue split.

Victims
1
 
First Discovered
2026-07-06
victim
Last Discovered
2026-07-06
victim
Inactive Since
28
days
Avg Delay
98
days
Infostealer
0.0%
victims with domain
Countries
1
hit
View Victims on World Map View Group Statistics
Attack Velocity — Last 12 months

Known Locations (2)
Favicon Title Type Available Last Visit Server Info FQDN
favicon cry0 blog Yes 2026-08-03T06:13:19 cryoblogedawivdcknyd4jsjxkrx3xrqqltxla6wwjjnzm3f3jaxjzqd.onion
favicon No 2026-08-03T06:12:31 pwn3dky35tub4ktj5bolc72oezg6qc3jvmbogaiwwkimiqtbbokyhrid.onion

Target
Top 5 Activity Sectors
  • Transportation 1
Top 5 Countries
  • IT flag Italy 1

Heatmap

YARA Rules (1)

Indicators of Compromise (IoCs) (2)
IP Address 1 tox 1
Type IOC
IP Address 45.227.253.59:3111
tox 54E9450799AFBBA90992E3C40F552C8C05D5765144396C6A1A622FD9DABD01101F9DC0CF90F4

Victims (1)
Logo
Discovered: 2026-07-06 (27d ago)  ·  Attack est.: 2026-03-30
DINI is a family-run transportation and automotive business base...…