CiberLATAMbywhalemate

Brazilian domains added to DragonForce, KRYBIT

Frato, neooftalmo.com.br and sysconth.com appear among new DragonForce and KRYBIT victims, with outside checks refining the claims.

Whalemate Labs · AI-assisted researchPublished:Updated 3 min read

Security Arsenal detected new victims of DRAGONFORCE, KRYBIT, BARRACUDA, STORM and other groups, with cases in Argentina, Brazil and Guatemala. Frato, neooftalmo.com.br and sysconth.com were added, with external cross-checks in some cases.

Update August 31, 2026: The review now includes the naming of Frato as a DragonForce victim, the frato.com domain, and additional BreachSense context on exposed credentials. It also adds two Brazilian domains claimed by KRYBIT, neooftalmo.com.br and sysconth.com, along with external cross-checks that temper the public confirmation of those cases.

Security Arsenal recorded a string of ransomware campaigns in August 2026 with new victims in the United States and Latin America, including organizations in Argentina, Brazil and Guatemala. Across the batches attributed to DRAGONFORCE, KRYBIT, BARRACUDA, STORM, GLOBAL SECRET GROUP, COINBASECARTEL, METAENCRYPTOR and CHAOS, the same tactics kept appearing: initial access through VPN or RMM, lateral movement with PsExec and WMI, and pre-encryption preparation that included shadow copy deletion and file staging.

What did the most active batch in the region show?

Security Arsenal said DRAGONFORCE disclosed four new victims in 24 hours and that the observed pattern included VPN or RMM abuse, lateral movement with PsExec and WMI, shadow copy destruction and staging before encryption. In that same analysis, the firm placed victims in Argentina and Brazil within the campaign-linked group, including Criba in Argentina and Frato in Brazil, and it identified Frato in the Other sector, classified as Industrial/HVAC Engineering, tied to the frato.com domain.

BreachSense reinforced that attribution by listing Frato as a victim linked to DragonForce in its own breach database, with frato.com as the affected domain. The same record added that 71 accounts with @frato.com email addresses had been exposed in earlier external breaches, along with 86 credentials related to frato.com, broadening the risk surface beyond the incident posted by the group.

Security Arsenal also described the sectors hit in that DragonForce wave as technology, financial services and industry or engineering, with a geographic footprint in South America, including Brazil. Tanium added more technical context by noting that DragonForce exploits known flaws, such as Ivanti Connect Secure and Log4Shell-type vulnerabilities, and that it sometimes relies on initial access brokers like Scattered Spider, although that point is presented as the source's own characterization.

What happened with KRYBIT and other groups?

KRYBIT posted 13 organizations in 48 hours and, according to Security Arsenal, used ingress through edge or RMM, lateral movement with WMI and PsExec, and pre-encryption staging with shadow copy deletion and mass file staging. That batch included victims in Brazil, Guatemala and the United States, with a sector concentration in healthcare, agriculture or food production, and retail or e-commerce.

Among the Brazilian cases, Security Arsenal said KRYBIT included neooftalmo.com.br and sysconth.com. In the first case, Ransomware.live listed the entry with a discovery date of August 26, 2026, and MedRisk explained that it refers to NEO Núcleo de Excelência em Oftalmologia, an eye hospital in Brazil that operates that domain and was placed in a healthcare sub-wave of the group.

The claim over neooftalmo.com.br was also backed by Breach House, which logs the incident as a KRYBIT attack against www.neooftalmo.com.br and marks the country as Brazil. RecentBreaches, meanwhile, classifies the case as an unconfirmed claim, warns that the listing still lacks public confirmation and regulatory support, and says the only available reference comes from the group's leak site.

At the same time, MedRisk noted that KRYBIT's claims against healthcare targets have not been publicly confirmed by the affected organizations. RecentBreaches said the same and added that the neooftalmo.com.br profile remains an unconfirmed breach claim, with no supporting entries in regulatory indexes or consolidated breach databases.

The second domain, sysconth.com, also appears in outside sources. RecentBreaches lists it as a KRYBIT ransomware claim dated August 26, 2026 and associates it with Syscon (Thailand) Co., Ltd., while DisclosureLens reported that the group says it published data and that no regulatory documentation has yet corroborated the alleged breach.

Breach House, for its part, records the attack against sysconth.com, with Brazil as the country and IT as the sector. That framing adds a supply-chain risk angle for customers or partners that depend on that provider, although the claim remains publicly unconfirmed and without regulatory backing according to the external sources reviewed.

What technical pattern repeats across these intrusions?

The campaigns tracked by Security Arsenal show a very similar operating playbook across groups: initial access through exposed devices or remote services, RMM abuse, lateral execution with PsExec and WMI, shadow copy deletion and staging before encryption. GLOBAL SECRET GROUP fits that pattern, with three victims in 24 hours and TTPs that include initial access through edge devices, RMM abuse, lateral movement with PsExec and WMI, VSS deletion and pre-encryption data staging.

The same logic appears in METAENCRYPTOR, which posted seven victims in 24 hours and included organizations in the United States in energy or utilities, agriculture or food, and manufacturing. CHAOS also added three new victims in 24 hours, with cases in the United States and a focus on professional services and SMBs. COINBASECARTEL, in turn, posted 13 victims in 24 hours, with cases in the United States across sectors such as professional services and healthcare.

How does Medusa fit into this picture?

CISA, the FBI and the U.S. Department of Health and Human Services updated advisory AA25-071A on Medusa ransomware on August 18, 2026, and said the group exploits remote monitoring and management software and remote access services, including RDP, to move inside networks before deploying encryption and double extortion. The agencies also said Medusa has affected more than 500 organizations worldwide and that healthcare is among the most impacted sectors.

The same approach appears in a legal-technical analysis published on August 23, 2026, which highlighted the use of legitimate remote monitoring software to evade detection, exfiltrate data and deploy encryption. The overlap between the official alerts and the technical reports reinforces the view that abuse of RMM and remote access remains a central vector for fast-moving campaigns, with double extortion and a strong focus on healthcare and corporate environments.

Sources

View all