Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Kyber ransomware is not just post-quantum name-dropping

1b66614d63ce9f1b0b9f68464a93d826a3af7e08ccadcbc662f8444f0eaab6b9

TLP:CLEAR
Active

sha256

Description

A detailed technical analysis confirms that Kyber ransomware implements genuine hybrid post-quantum cryptography rather than mere branding. The Rust-based Windows variant encrypts files using AES-256-CTR with Kyber1024 and X25519 for key protection, appending a fixed 0x744-byte trailer containing encrypted metadata. Instrumented analysis validated the cryptographic implementation through fixture decryption but found no practical recovery path from the sample alone. The encryptor targets multiple file types, deploys standard recovery-inhibition techniques, and marks encrypted files with a .#~~~ extension. A separate ESXi variant was found to use different cryptography despite similar branding. As of April 2026, one victim was publicly listed: a large American defense contractor and IT services provider.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Kyber ransomware is not just post-quantum name-dropping
Pattern Type
STIX
Confidence
75%
Valid From
May 3, 2026 00:55
Total Sightings
0
Added
May 3, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of 1b66614d63ce9f1b0b9f68464a93d826a3af7e08ccadcbc662f8444f0eaab6b9

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.