logo

Kyber ransomware gang toys with post-quantum encryption on Windows

ID: 6faa76fd-8cdf-5a88-a24f-19d72dc53ea9

STIX ID: report--6faa76fd-8cdf-5a88-a24f-19d72dc53ea9

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-04-22

Date Updated: 2026-04-22

Author: Bill Toulas

...
...

Rapid7 and BleepingComputer describe a Kyber ransomware campaign deploying two distinct variants on the same network: a Linux/ESXi encryptor that targets VMware datastores (using ChaCha8 and RSA-4096 despite claims of Kyber1024) and a Rust-written Windows variant that implements Kyber1024 for key protection and performs destructive actions (terminating services, deleting backups, killing VMs). Both share a Tor-based ransom infrastructure and campaign ID, with at least one high-value victim listed on the extortion site; the report highlights differences in maturity between the variants and details TTPs used to maximize impact and prevent recovery.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.