
Sinobi is a financially motivated, closed vetted-affiliate RaaS operation assessed with medium confidence as a rebrand/successor of Lynx (itself INC-derived). Active since late June 2025, it gains access primarily via compromised SonicWall SSL VPN credentials and over-privileged accounts, removes EDR, exfiltrates with RClone and WinSCP, then deploys a Curve25519/AES-128-CTR locker that deletes shadow copies and appends .SINOBI — enforcing double extortion with a 7-day deadline. 250+ leak-site victims by May 2026. A serious mid-market threat through 2026.
TA2026169.SINOBI locker, Lynx-derived code and infrastructureSinobi is a financially motivated ransomware-as-a-service operation that emerged in late June 2025, running a closed, vetted-affiliate model where a core team maintains the encryptor, infrastructure, and negotiation/leak portals while screened affiliates conduct intrusions. Code and data-leak-site overlaps support a medium-confidence assessment that Sinobi is a rebrand or successor of Lynx, itself derived from INC ransomware source code sold in May 2024 for $300,000. Despite shinobi branding, consistent avoidance of Russia/CIS victims points to Russian or Eastern-European cybercrime.
Sinobi targets mid-to-large organizations with $10–50 million annual revenue, primarily in the United States. The top 2025 vertical was Manufacturing, followed by Construction, Healthcare, Technology, and Business Services. The operation scaled from ~40 victims in Q3 2025 to 250+ listed by May 2026. Given its inherited tooling maturity, rapid victim accumulation, credential-led intrusion model, and recovery-inhibition tradecraft, Sinobi should be treated as a serious mid-market threat through 2026.
| CVE ID | Vulnerability Name | Affected Product | Zero-Day | CISA KEV | Patch |
|---|---|---|---|---|---|
CVE-2024-53704 | SonicWall SonicOS SSLVPN Improper Authentication Vulnerability | SonicWALL NSv devices · SonicWall SSLVPN | ✗ No | ✓ Yes | ✓ Yes |
CVE-2024-40766 | SonicWall SonicOS Improper Access Control Vulnerability | SonicWall SonicOS | ✗ No | ✓ Yes | ✓ Yes |
CVE-2024-53704 (SSL VPN authentication bypass) and CVE-2024-40766 (improper access control — a credential-carryover flaw exploited by multiple ransomware groups during Gen 6→Gen 7 SonicWall migrations). Phishing and initial-access-broker credentials are also reported vectors..SINOBI, and writes a README.txt note with Tor negotiation links and a 7-day deadline. The desktop wallpaper is replaced. Double extortion is enforced: pay the ransom or stolen data is published on the Sinobi leak site.CVE-2024-40766 and CVE-2024-53704. Because CVE-2024-40766 is a credential-carryover flaw from Gen 6 to Gen 7 firewall migrations, reset all local SSL VPN account passwords imported during migration — patching alone is insufficient.sc config start= disabled ), and never store EDR uninstall or deregistration codes on file shares or mapped drives.net user ... /add followed by net localgroup "domain admins" ... /add from a single session. Restrict net, net localgroup, and sc config execution from non-administrative hosts. Monitor RDP and network-share access between internal systems.| Type | Value |
|---|---|
| SHA256 |
|
| SHA1 |
|
| File Paths |
|
| Registry Key | HKCU\Control Panel\Desktop\Wallpaper |
| File Extension | .SINOBI |
| Tor Domains |
|
| Tactic | Technique | Sub-technique & Notes |
|---|---|---|
| Initial Access | T1133 | External Remote Services — SonicWall SSL VPN credential abuse; over-privileged MSP domain-admin account enables RDP to file server |
| Initial Access | T1078 | T1078.002 Domain Accounts — compromised VPN credentials for over-privileged domain-administrator accounts; also IAB-sourced credentials |
| Initial Access | T1190 | Exploit Public-Facing Application — CVE-2024-53704 (SSLVPN auth bypass) and CVE-2024-40766 (improper access control / credential carryover) |
| Execution | T1059 | T1059.003 Windows Command Shell — post-compromise scripting for account creation, lateral movement, and encryptor deployment |
| Persistence | T1136 | T1136.001 Local Account — rogue local accounts created and elevated to local Administrators and Domain Admins for persistence and lateral movement |
| Persistence | T1543 | T1543.003 Windows Service — services modified or created to maintain persistence across the compromised environment |
| Priv Escalation | T1134 | Access Token Manipulation — elevated privileges used to operate with domain admin context across compromised network |
| Priv Escalation | T1098 | Account Manipulation — rogue accounts elevated into Domain Admins group via net localgroup "domain admins" /add |
| Defense Evasion | T1562 | T1562.001 Disable/Modify Tools — Carbon Black EDR uninstalled using deregistration code stored on a network share |
| Discovery | T1082 | System Information Discovery — host profiling to identify backup agents, databases, and mail servers for termination before encryption |
| Discovery | T1057 | Process Discovery — enumerates running backup, database, and mail processes for pre-encryption termination |
| Discovery | T1083 | File and Directory Discovery — file system enumeration to identify high-value data for exfiltration staging |
| Discovery | T1135 | Network Share Discovery — network shares enumerated for lateral movement and data staging via RClone/WinSCP |
| Discovery | T1087 | Account Discovery — existing accounts enumerated to identify targets for privilege escalation and lateral movement |
| Lateral Movement | T1021 | T1021.001 RDP / T1021.002 SMB — lateral movement via RDP and shared mounts across compromised network |
| Credential Access | T1003 | OS Credential Dumping — credentials harvested post-compromise to support lateral movement and privilege escalation |
| Collection | T1005 | Data from Local System — sensitive data collected from compromised file servers prior to exfiltration |
| C2 | T1090 | T1090.003 Multi-hop Proxy — Tor onion domains used for negotiation and leak-site communications |
| Exfiltration | T1567 | T1567.002 Exfiltration to Cloud Storage — RClone and WinSCP used to transfer stolen data to cloud storage before encryption |
| Impact | T1486 | Data Encrypted for Impact — Curve25519/AES-128-CTR per-file encryption with CryptGenRandom; appends .SINOBI; no cryptographic decryption shortcut |
| Impact | T1489 | Service Stop — backup, database, and mail processes optionally terminated before encryption to maximize file access |
| Impact | T1490 | Inhibit System Recovery — volume shadow copies deleted via low-level DeviceIoControl resize; Recycle Bin emptied before encryption |