Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors weyhro

Description

Weyhro is a data-extortion group (relying on data theft and leak threats without file encryption) that launched a Tor leak site in March 2025, focusing on manufacturing, financial services, and real estate sectors with victims in the US, Italy, and Canada. Known victims: 14

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

Weyhro is a data-extortion group leveraging Tor-based leak sites to threaten data publication rather than file encryption, targeting manufacturing, financial services, and real estate sectors in the US, Italy, and Canada. With 14 confirmed victims since late 2024, the group operates with medium sophistication and focuses on organizational gain through ransom demands.

Goals & Targeting

Weyhro’s primary motivation is financial gain through ransom demands, targeting sectors with high-value data assets, including manufacturing, financial services, and real estate. The focus on these sectors may stem from their critical role in global supply chains, the sensitivity of financial data, and the potential for high ransom payouts. The group’s geographic targeting of the US, Italy, and Canada suggests a strategic focus on regions with strong economic infrastructure and potentially less robust cybersecurity defenses in targeted organizations.

Enhanced Description

Weyhro is a criminal data-extortion group that emerged in late 2024, characterized by its reliance on data theft and leak threats without resorting to file encryption. The group established a Tor-based leak site in March 2025, targeting high-value sectors such as manufacturing, financial services, and real estate, with confirmed victims in the United States, Italy, and Canada. Unlike traditional ransomware operators, Weyhro prioritizes data exfiltration and extortion, leveraging the threat of public disclosure to extract ransom payments. While the group’s technical tactics are not explicitly detailed, the use of IP addresses in linked IOCs suggests network-based infiltration methods. The actor’s operations remain largely constrained to non-encryption-based extortion, distinguishing it from more sophisticated state-sponsored or advanced persistent threat (APT) groups.

Key Capabilities

  • Data exfiltration and leak threat operations
  • Use of Tor-based infrastructure for command and control (C2)
  • Targeted phishing or network infiltration tactics
  • Leveraging IP-based infrastructure for lateral movement or data exfiltration

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Exfiltration
Command and Control

ATT&CK Techniques

T1136.001
T1059.003
T1566.001
T1102.001

Software / Tooling

Custom data-exfiltration malware
Tor-based C2 infrastructure
Phishing toolkits for initial compromise

Campaigns & Victims

Weyhro’s campaigns revolve around data extortion via Tor-based leak sites, with a focus on manufacturing, financial services, and real estate. The group’s operational tempo appears moderate, with 14 confirmed victims since late 2024, suggesting a sustained but not highly aggressive campaign. Victim attribution to the US, Italy, and Canada indicates a pattern of targeting geographically dispersed but economically significant regions. Notably, the absence of encrypted files in reported incidents distinguishes Weyhro from traditional ransomware groups, aligning it with newer extortion models that prioritize data theft and disclosure.

IOC Patterns

  • Spear-phishing with malicious payloads leading to data exfiltration
  • C2 infrastructure hosted on Tor or bulletproof hosting services
  • Lateral movement via IP-based network exploitation

Recommended Actions

  • Implement strict network segmentation to limit data exfiltration pathways
  • Deploy advanced email filtering and employee training to detect phishing attempts
  • Monitor for unauthorized access to sensitive data repositories
  • Use threat intelligence feeds to track Tor-based C2 domains or IP addresses
  • Conduct regular backups and ensure offline storage to mitigate extortion demands

Suggested Tags

criminal
ransomware
data-theft
financial-gain
manufacturing-sector
financial-services
real-estate-sector

Confidence Assessment

The assessment is based on limited data, primarily IOCs (IP addresses) and confirmed victims. While the group’s targeting sectors and operational model are clear, there is insufficient information about specific attack chains, tools, or MITRE techniques. Confidence in key capabilities and TTPs is moderate, with gaps in understanding the full scope of network infiltration methods and lateral movement strategies.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

2

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Data Exfiltration
Data extortion
Criminal
Manufacturing sector
Financial services
Real estate sector
North America
Europe
criminal
ransomware
data-theft
financial-gain
manufacturing-sector
financial-services
real-estate-sector

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Dec 12, 2024
Last Seen
Aug 10, 2025
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.