HackerFeeds
All ransomware groups

sinobi

274 tracked victims
·first seen 2025-03-24·last activity 2026-05-05

Group profile

Sinobi is a private vetted-affiliate RaaS group that emerged in mid-2025, believed to be a rebrand of the Lynx/INC ransomware lineage, claiming 176 victims by end of 2025 through double-extortion attacks primarily against mid-market US organizations via compromised SonicWall VPN credentials.

MITRE ATT&CK TTPs

TA0001

Initial Access

  • T1078Valid Accounts

    Use of valid credentials from MSPs (Managed Service Providers).

  • T1190Exploit Public-Facing Application

    Exploitation of vulnerabilities in VPNs (SonicWall).

  • T1566Phishing

TA0002

Execution

  • T1059.001Command and Scripting Interpreter: PowerShell

    Heavy use of PowerShell for script and in-memory command execution.

  • T1059.003Command and Scripting Interpreter: Windows Command Shell

  • T1106Native API

  • T1203Exploitation for Client Execution

  • T1569.002System Services: Service Execution

TA0003

Persistence

  • T1543.003Create or Modify System Process: Windows Service

    Creation or modification of Windows services to ensure malware restart.

TA0004

Privilege Escalation

  • T1068Exploitation for Privilege Escalation

TA0005

Defense Evasion

  • T1027Obfuscated Files or Information

  • T1070Indicator Removal

    Removal of event logs.

  • T1070.004Indicator Removal: File Deletion

  • T1562.001Impair Defenses: Disable or Modify Tools

    Active disabling of EDR solutions (such as VMware Carbon Black).

TA0007

Discovery

  • T1046Network Service Discovery

  • T1083File and Directory Discovery

  • T1087.002Account Discovery: Domain Account

TA0008

Lateral Movement

  • T1021.001Remote Services: Remote Desktop Protocol

    Use of RDP to navigate between servers after privilege escalation.

TA0010

Exfiltration

  • T1567.002Exfiltration Over Web Service: Exfiltration to Cloud Storage

    Use of Rclone tool to send data to public cloud providers before encryption.

TA0011

Command and Control

  • T1573.001Encrypted Channel: Symmetric Cryptography

TA0040

Impact

  • T1486Data Encrypted for Impact

    Data encryption via AES-128-CTR and Curve-25519, adding the .SINOBI extension.

  • T1489Service Stop

  • T1490Inhibit System Recovery

    Deletion of Shadow Copies via vssadmin.exe.

TA0042

Resource Development

Recent victims

showing 50 of 274
DateWebsite / victimSectorCountry
2026-05-05
neurotrials.com
Neurotrials Research Incneurotrials.com
HealthcareUS
2026-05-05
scalesassoc.com
Scales and Associates Incscalesassoc.com
Business ServicesUS
2026-05-05
P
Positiwise Infotech Pvt
TechnologyIN
2026-05-05
C
Celeris Networks
Technology
2026-05-05
B
Bay State Land Services
ConstructionUS
2026-05-05
U
Unre3d
Not Found
2026-03-17
elgielectric.com
Elgi Electric & Industrieselgielectric.com
ManufacturingIN
2026-03-17
ourams.com
Amerinational Management Services (AMS)ourams.com
Business ServicesUS
2026-03-17EnergyUS
2026-03-17
interpacknorthwest.com
Interpack Northwestwww.interpacknorthwest.com
Agriculture and Food ProductionUS
2026-03-17
ecosoundbuilders.com
Eco Sound Builderswww.ecosoundbuilders.com
ConstructionUS
2026-03-17
mcafeetool.com
McAfee Tool & Diemcafeetool.com
ManufacturingUS
2026-03-17EnergyUS
2026-02-19TechnologyUS
2026-02-19TechnologyGB
2026-02-19TechnologyUS
2026-02-19TechnologyUS
2026-02-19ManufacturingUS
2026-02-19
mayfairhotels.com
Mayfair Hotels & Resortswww.mayfairhotels.com
Hospitality and TourismIN
2026-02-10
halcyontechnologies.com
Halcyon Technologieswww.halcyontechnologies.com
TechnologyUS
2026-02-10TechnologyUS
2026-02-10
sundhergroup.com
The Sundher Groupsundhergroup.com
Agriculture and Food ProductionCA
2026-02-10Business ServicesUS
2026-02-10Consumer ServicesUS
2026-02-10TechnologyUS
2026-02-05Financial ServicesUS
2026-02-05ConstructionUS
2026-02-05Business ServicesUS
2026-02-05TechnologyCA
2026-02-05
wsiron.com
Western Slope Iron & Supplywsiron.com
ManufacturingUS
2026-02-05
reillyfoam.com
Reilly Foam Corpwww.reillyfoam.com
ManufacturingUS
2026-01-27ManufacturingUS
2026-01-27
impressico.com
Impressico Business Solutionsimpressico.com
TechnologyIN
2026-01-27
affordablehousingmanagementmetrics.com
Affordable Housing Management Overview Metricsaffordablehousingmanagementmetrics.com
ConstructionUS
2026-01-27
activegreenross.com
Active Green + Rosswww.activegreenross.com
Consumer ServicesCA
2026-01-27TechnologyUS
2026-01-27Consumer ServicesIT
2026-01-27
morisoninsurance.com
Morison Insurance Brokerswww.morisoninsurance.com
Financial ServicesCA
2026-01-27
gallaghertransport.com
Gallagher Transport Internationalgallaghertransport.com
Transportation/LogisticsUS
2026-01-27ManufacturingUS
2026-01-21
westcarygroup.com
West Cary Groupwww.westcarygroup.com
Business ServicesUS
2026-01-21Consumer ServicesUS
2026-01-21HealthcareUS
2026-01-21
asianheartinstitute.org
Asian Heart Institutewww.asianheartinstitute.org
HealthcareIN
2026-01-21
modernisticgardenpetsupply.com
MODERNISTIC GARDEN & PET SUPPLY LTDwww.modernisticgardenpetsupply.com
Consumer ServicesBS
2026-01-21Business ServicesUS
2026-01-18
talleyvillefire.com
Talleyville Firewww.talleyvillefire.com
Public SectorUS
2026-01-18
pivotalhealthcare.com
Pivotal Healthcarewww.pivotalhealthcare.com
HealthcareUS
2026-01-18EnergySI
2026-01-18Hospitality and TourismUS