sinobi
RansomwareAbout the group
Sinobi is a private vetted-affiliate RaaS group that emerged in mid-2025, believed to be a rebrand of the Lynx/INC ransomware lineage, claiming 176 victims by end of 2025 through double-extortion attacks primarily against mid-market US organizations via compromised SonicWall VPN credentials.
Exploited vulnerabilities
No CVEs attributed to this group in public sources (MITRE ATT&CK). Absence of attribution does not mean absence of activity.
Impact and victims
The group sinobi has 1 known ransomware victims. See the most affected sectors and countries and recent victims.
1known victims
1in Brazil
1sectors hit
Most attacked sectors
Manufacturing1
Most affected countries
🇧🇷 Brasil1
Recent victims
Galutti Automotive Industria Metalurgica Ltda
References
sinobi uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.
Explore the AI Autonomous Pentest →