Weyhro is a data-extortion group (relying on data theft and leak threats without file encryption) that launched a Tor leak site in March 2025, focusing on manufacturing, financial services, and real estate sectors with victims in the US, Italy, and Canada. Known victims: 14
Objectives
Executive Summary
Weyhro is a data-extortion group leveraging Tor-based leak sites to threaten data publication rather than file encryption, targeting manufacturing, financial services, and real estate sectors in the US, Italy, and Canada. With 14 confirmed victims since late 2024, the group operates with medium sophistication and focuses on organizational gain through ransom demands.
Goals & Targeting
Weyhro’s primary motivation is financial gain through ransom demands, targeting sectors with high-value data assets, including manufacturing, financial services, and real estate. The focus on these sectors may stem from their critical role in global supply chains, the sensitivity of financial data, and the potential for high ransom payouts. The group’s geographic targeting of the US, Italy, and Canada suggests a strategic focus on regions with strong economic infrastructure and potentially less robust cybersecurity defenses in targeted organizations.
Enhanced Description
Weyhro is a criminal data-extortion group that emerged in late 2024, characterized by its reliance on data theft and leak threats without resorting to file encryption. The group established a Tor-based leak site in March 2025, targeting high-value sectors such as manufacturing, financial services, and real estate, with confirmed victims in the United States, Italy, and Canada. Unlike traditional ransomware operators, Weyhro prioritizes data exfiltration and extortion, leveraging the threat of public disclosure to extract ransom payments. While the group’s technical tactics are not explicitly detailed, the use of IP addresses in linked IOCs suggests network-based infiltration methods. The actor’s operations remain largely constrained to non-encryption-based extortion, distinguishing it from more sophisticated state-sponsored or advanced persistent threat (APT) groups.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Weyhro’s campaigns revolve around data extortion via Tor-based leak sites, with a focus on manufacturing, financial services, and real estate. The group’s operational tempo appears moderate, with 14 confirmed victims since late 2024, suggesting a sustained but not highly aggressive campaign. Victim attribution to the US, Italy, and Canada indicates a pattern of targeting geographically dispersed but economically significant regions. Notably, the absence of encrypted files in reported incidents distinguishes Weyhro from traditional ransomware groups, aligning it with newer extortion models that prioritize data theft and disclosure.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The assessment is based on limited data, primarily IOCs (IP addresses) and confirmed victims. While the group’s targeting sectors and operational model are clear, there is insufficient information about specific attack chains, tools, or MITRE techniques. Confidence in key capabilities and TTPs is moderate, with gaps in understanding the full scope of network infiltration methods and lateral movement strategies.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
2
IOCs
0
Observed Data
0
Tactics