Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.
Sinobi is a private, vetted-affiliate ransomware-as-a-service operation that emerged publicly in late June / early July 2025. It runs a double-extortion model with a Tor-based data leak site whose infrastructure closely mirrored earlier Lynx sites, and is widely assessed to be a rebrand/successor in the INC -> Lynx -> Sinobi lineage. Reported initial access relies heavily on compromised SonicWall SSL VPN credentials and unpatched SonicWall devices (CVE-2024-40766, CVE-2024-53704), with some reporting of Oracle E-Business Suite exploitation (CVE-2025-61882). Victims skew toward mid-market and larger US organizations across manufacturing, professional services, healthcare, technology and retail.
Sinobi was first flagged by trackers around 5 July 2025 after Tor leak infrastructure was observed in late June 2025 mirroring Lynx sites, suggesting staging before public emergence. Activity ramped through July 2025 and continued steadily through the rest of the year; ransomware.live records the operation claiming on the order of 270+ victims by end of 2025, heavily concentrated in the United States (roughly 205), with smaller tallies in India, the United Kingdom, France and Taiwan. Analysts characterize it as a semi-private RaaS with a small core team and strictly screened affiliates. Technical lineage to Lynx and INC is supported by leak-site infrastructure reuse, TTP overlap and reported binary code similarity (~63% vs Lynx, ~56% vs INC). Per ransomware.live the group went quiet in 2026, last seen around 8 May 2026 and inactive for ~120 days as of mid-2026; whether this is a pause, wind-down or further rebrand is unconfirmed.
MENA relevance: The Saudi Arabia tag is not clearly supported by the vendor reporting reviewed (Barracuda, eSentire, Blackpoint and Halcyon describe predominantly US/Canada/Australia/European victimology), and no Saudi Arabian entry appears on ransomware.live at the time of writing — treat the Saudi tag as unverified / low-confidence. Sinobi is not a MENA-focused actor.
+21 more relationships — see the relationships browser.
These entities are frequently mentioned together in source material; co-occurrence is not a verified relationship.