CiberLATAMbywhalemate

KRYBIT Hits Brazil and Guatemala in 48 Hours

KRYBIT named 13 victims in 48 hours, including cases in Brazil and Guatemala. Health, agriculture, retail and finance were among the targets.

Whalemate Labs · AI-assisted researchPublished:3 min read

KRYBIT posted 13 organizations as victims on its leak site between Aug. 24 and Aug. 26, 2026, with cases spread across Brazil and Guatemala. The wave reached health care, agriculture and food production, retail and e-commerce, financial services, and a technology company in Brazil.

KRYBIT posted 13 organizations as victims on its leak site in a 48-hour window between Aug. 24 and Aug. 26, 2026. Confirmed cases include organizations in Brazil and Guatemala, with exposure across health care, agriculture and food production, retail and e-commerce, plus a financial services victim and a technology company in Brazil.

Which sectors appear most exposed in this wave?

The sectors most represented in KRYBIT’s publication were agriculture and food production, health care, and retail and e-commerce, according to Security Arsenal’s analysis. The same report also adds a victim in financial services and another technology company in Brazil, pointing to a campaign with broad reach and a regional footprint.

Breachsense added two identifications that help clarify that picture. Núcleo de Excelência em Oftalmologia, an ophthalmology hospital network in Brazil, is listed as a KRYBIT victim, reinforcing the impact on the health sector in that country. Ferretornillos, S.A., a distributor of hardware and industrial supplies in Guatemala, was also cataloged as an incident attributed to the group, giving the wave a more precise business profile and confirming its presence in industrial and agroindustrial supply chains in the region.

What is known about Aurora in Latin America?

A report on the Aurora operation describes ransomware affiliate activity between April and July 2026 with victims in several countries, including Argentina. The material attributes to the operator a set of offensive tactics that includes BloodHound, NetExec, PetitPotam, Coerce Plus, PrinterBug, ntlmrelayx, Certipy, xp_cmdshell, GodPotato and DCSync, along with exfiltration to self-hosted S3-compatible storage.

Inside Telecom says Aurora’s sample covered industries such as manufacturing, food and agriculture, professional and financial services, transportation and logistics, consumer goods, environmental services, and IT and backup infrastructure. The same source says the United States accounted for the largest share of confirmed victims in the set analyzed.

GBHackers, citing CloudSEK, expands that picture with a technical analysis of an Aurora affiliate active between April and July against more than 20 organizations in nine countries. The report describes an exposed directory with credentials, Kerberos tickets, shell histories, Cursor chat logs, custom NetExec modules, and Aurora binaries for Windows and Linux compiled from the same Zig codebase.

What other recent campaigns follow this pattern?

Security Arsenal also reported three CHAOS ransomware victims in 48 hours, with initial access techniques that include exposed RDP, weak or missing MFA on VPNs and perimeter defenses, phishing with Office attachments containing macros, abuse of RMM tools such as ScreenConnect, and web shells in Exchange and IIS. The finding adds to a recent string of ransomware group publications focused on initial access, lateral movement and exfiltration.

Sources

View all