Uptime Hamster: 27d 12h 33mDeploy: 3 Aug 2026 06:56Updated: 2026-07-21
Logo del actor de amenaza weyhro

weyhro

2 incidentes 2 paises 1 sectores threat-actor RU Ultimo: 2026-06-29
Ver en IntelTracker → APTTrail →
Weyhro is a financially motivated data extortion group that emerged in late 2024, rapidly gaining prominence on underground forums by December of that year and launching its dedicated Tor-based leak site by March 2025. While some reports characterize Weyhro primarily as a data exfiltration group operating without file encryption, others indicate they engage in double extortion, which includes both data theft and encryption. A distinguishing characteristic of this threat actor is the alleged shift of its operator, as of December 2025, towards selling a sophisticated command-and-control (C2) toolkit called Weyhro C2, marketed for advanced penetration testing and stealth operations, signaling a potential expansion of their criminal enterprise beyond direct ransomware attacks to enabling other cybercriminals. The group's activities include a notable restriction on its toolkit from operating within Commonwealth of Independent States (CIS) systems, a common tactic among Russian or Eastern Eu

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / leak siteunknownransomware.anggipradana.comRansomware Group: weyhro
DLS / onionofflinextxtpqpyaaek4p4525ksepyyy75gfvi47fptm2gftw7cn656rnfhzdqd.onionCTI.FYI
DLS / leak siteissueweyhro.hkCTI.FYI
DLS / onionofflineweyhro27ruifvuqkk3hxzcrtxv2lsalntxgkv6q2j3znkhdqudz54rqd.onionCTI.FYI
DLS / onionofflineweyhro27ruifvuqkk3hxzcrtxv2lsalntxgkv6q2j3znkhdqudz54rqd.onionCTI.FYI
Webonlineweyhro.hkCTI.FYI
DLS / onionunknownweyhro27ruifvuqkk3hxzcrtxv2lsalntxgkv6q2j3znkhdqudz54rqd.onionmarktsec
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

Canada (1) United States (1)

Paises objetivo (OSINT)

AustraliaBarbadosCanadaGermanyUnited KingdomIndiaItalyComorosSomaliaThailand

Sectores atacados

Manufacturing (1)

Sectores objetivo (OSINT)

Construction of BuildingsOther Information ServicesSoftware PublishersReal EstateEnterprises & HoldingManufacturingConstructionPublic AdministrationAdministrative &Waste Management Educational Services

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com