CiberLATAMbywhalemate

KRYBIT and LOCKBIT5 Add New Victims

KRYBIT, LOCKBIT5, and INC Ransom added new victims, with most activity centered on the United States and fresh listings in 48 and 24 hours.

Whalemate Labs · AI-assisted researchPublished:3 min read

Security Arsenal logged 13 KRYBIT victims in 48 hours and five LOCKBIT5 victims in 24 hours, while INC Ransom added more cases tied to Ruby Seven Studios, Bencivil, and Oilquip Inc.

Security Arsenal reported that KRYBIT added 13 organizations to its leak site in a 48-hour window between Aug. 24 and Aug. 26, 2026. The victims were spread across India, Brazil, Guatemala, Gabon, Vietnam, the United States, and Germany. In that analysis, the source identified wmiemporium.com as a U.S. victim in the Retail and E-Commerce sector. Ransomware.live added that the entry was discovered on Aug. 26, 2026, and that the estimated attack date was also Aug. 26.

What did the LOCKBIT5 campaign show?

Security Arsenal said LOCKBIT5 added five new victims in 24 hours, with targets in Tunisia, the Netherlands, Belgium, Czechia, and the United States. Within that campaign, the source identified theheartcenterofmemphis.com as a U.S. victim in Healthcare. The same analysis pointed to a sector focus on healthcare, professional services, and technology.

What did RST Cloud’s report on Aurora show?

RST Cloud published The Aurora Files, a report that describes activity from an Aurora ransomware affiliate and lists TTPs including Bloodhound, Petitpotam, Printerbug, Eternalblue, Kerberoasting, AS-REP roasting, Netexec, shadow copy deletion, Certipy, Ntlmrelayx, DCSync, Kerbrute, Hashcat, Evil-WinRM, Chisel, Proxychains, and Metasploit. In its post, the account said the targets included manufacturing, food and agriculture, pharmaceutical and chemical distribution, and professional and consulting services, with a presence in the United States. RST Cloud later expanded on the information and said the exposed personal directory documented activity from April through July 2026, that the operator targeted more than 20 organizations in nine countries, gained domain-level or interactive access in 17 of them, and that four victims eventually appeared by name on Aurora’s leak site.

How did the Ruby Seven Studios case progress?

Ransomware.live maintains a listing for Ruby Seven Studios tied to INC Ransom, with a discovery date of Aug. 27, 2026, 114 GB of leaked data, 133,851 files, and 49,357 folders. GalaxyWarden added that the company was listed on INC Ransom’s leak site on Aug. 27 and that the group claims to have published a 114 GB archive with source code, game rules, assets, documents, financial reports, royalty statements, employee invention agreements, shareholder lists, and copies of identity documents or passports belonging to partners. RecentBreaches said the claim remains unverified and that the company has not issued a public confirmation. BreachSense placed the discovery date on Aug. 28 and described Ruby Seven Studios as a Nevada-based social casino gaming company focused on free-to-play apps.

What other INC Ransom victims appeared in the same wave?

GalaxyWarden documented that Benchmark Civil Engineering Services, Inc. was listed by INC Ransom on Aug. 27, 2026, and that there was no public confirmation from the company. RecentBreaches published a similar notice on Bencivil, warning that the entry suggests exposure of personal data for an unspecified number of individuals and that the claim is unverified. Darkfield later reported that Oilquip Inc was listed on Aug. 29, 2026, on INC Ransom’s leak site and linked to the specific post on the group’s Onion infrastructure, while GalaxyWarden said the group claims to have obtained internal data and that the company had not publicly confirmed the intrusion at the time of publication.

Sources

View all