logo

Dark Web Profile: Sinobi Ransomware

ID: 068615d8-1d4e-52da-bfcf-da535b8092f3

STIX ID: report--068615d8-1d4e-52da-bfcf-da535b8092f3

Feed Name: SOCRadar Blog

Threat Score
78/100

Date Published: 2026-02-17

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

This report profiles the Sinobi ransomware operation—likely a rebrand/continuation of Lynx and derived from INC source code—detailing its RaaS-like hybrid model, targets (manufacturing, healthcare, finance, education), double-extortion workflow, and full attack lifecycle from initial access (compromised credentials, CVE exploitation, phishing) through privilege escalation, EDR removal, data exfiltration (Rclone), and AES-128-CTR/Curve25519-based encryption. The analysis highlights code similarity metrics, leak site behavior, victim geography, observed TTPs (including disabling defenses and deleting Volume Shadow Copies), and defensive recommendations such as ASM, vulnerability intelligence, and dark web monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.