Unattributed cybercriminal ransomware-as-a-service (RaaS) operation. Multiple independent vendors (SoCRadar, Barracuda, eSentire, Blackpoint, Halcyon) assess with medium-to-high confidence that Sinobi is a rebrand or offshoot of the Lynx ransomware gang, which itself descended from the INC Ransom family (INC source code reportedly sold on underground forums in spring 2024 and acquired by Lynx operators). Binary code-similarity analysis reported publicly shows roughly 63% function overlap with Lynx and roughly 56% with INC. No nation-state attribution; no confirmed real-world identities. Lineage is a strong analytic assessment, not a confirmed fact.
First seen
2025-06
Last active
2026-05-08
Motivation
Financial (double-extortion ransomware: data theft plus encryption, with threat to publish exfiltrated data on a Tor leak site if the ransom is unpaid).
Attribution confidence
medium
MENA targeting
Saudi Arabia
Sectors
Agriculture/food
Corpus activity · 6mo1 mention
AMJJAS
Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.
Why it mattersRansomware actor, medium confidence, documented targeting Saudi Arabia (Agriculture/food sector).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.
No open hunts or recent alerts tracked against this actor right now.
Rows marked inferred are OSINT-extracted enrichment for actors without a MITRE Group ID — treat as analyst assessment, not authoritative ATT&CK attribution.
eSentire: 'sc config cbdefense start= disabled', binpath hijack of the Carbon Black service, and Revo Uninstaller used to remove EDR after locating the deregistration code.
eSentire: 'rclone.exe --config=c:\programdata\rclone-ssh.conf copy' to ASN 215540 infrastructure; Blackpoint/Barracuda: Rclone and WinSCP to cloud/offsite storage for double extortion.
Useful?
Related
Semantically related in the corpus — a discovery aid, not asserted attribution.
eSentire: shadow copies neutralised via DeviceIoControl IOCTL_VOLSNAP_SET_MAX_DIFF_AREA_SIZE (resize to 0) and Recycle Bin emptied via SHEmptyRecycleBinA.
eSentire observed 'cmd /c net user Assistance /add' creating a backdoor account (AttackIQ maps to T1136.001).
Regional co-occurrence · associated techniques
Honesty note
Regional co-occurrence is association, not prediction. These techniques appeared alongside Sinobi's activity across the tracked MENA roster — a TIE-style association computed on our corpus (not CTID's model), not a prediction of the next move. Ranked by support-adjusted lift (over-representation among actors like this one vs. the roster base rate, damped when few actors back it), so neither a merely-common technique nor a tiny-sample coincidence floats to the top. A hunting lead only; never recorded as observed. ICS techniques are excluded.
Which Microsoft 365 controls protect, detect, or respond to this actor's techniques — from the CTID Mappings Explorer (technique-level). Strength: significant / partial / minimal.
protect · 8 techniques
App GovernanceT1562significantDefender for Cloud AppsT1133partialDefender for Cloud AppsT1219significantDefender for Cloud AppsT1567partialDefender for Cloud AppsT1567.002partialConditional AccessT1078minimalID ProtectionT1098significantIdentity Secure ScoreT1078minimalMultifactor AuthenticationT1078minimalMultifactor AuthenticationT1098minimalPrivileged Identity ManagementT1078minimalPrivileged Identity ManagementT1098significantPrivileged Identity ManagementT1136partialPassword PolicyT1078significantPassword ProtectionT1078partialRole Based Access ControlT1078minimalRole Based Access ControlT1098partialRole Based Access ControlT1136minimalRole Based Access ControlT1562minimalAudit SolutionsT1078partialAudit SolutionsT1562partialInformation ProtectionT1567significant
detect · 10 techniques
App GovernanceT1078significantApp GovernanceT1562significantAdvanced Threat HuntingT1078significantAdvanced Threat HuntingT1562significantAdvanced Threat HuntingT1567significantDefender for Cloud AppsT1078partialDefender for Cloud AppsT1098minimalDefender for Cloud AppsT1133partialDefender for Cloud AppsT1219partialDefender for Cloud AppsT1486partialDefender for Cloud AppsT1567partialDefender for Cloud AppsT1567.002partialMicrosoft Defender for IdentityT1021minimalMicrosoft Defender for Identity
respond · 5 techniques
Automated Investigation and ResponseT1078significantAutomated Investigation and ResponseT1567significantIncident ResponseT1078minimalIncident ResponseT1098minimalIncident ResponseT1136minimalIncident ResponseT1562minimalConditional AccessT1078minimal
Countermeasures · D3FEND
Defensive techniques that counter Sinobi's TTPs, from MITRE D3FEND. The ATT&CK↔D3FEND link is mitigation-mediated — treat these as candidate countermeasures, not prescriptions.