PULSE NAME
Kyber ransomware is not just post-quantum name-dropping
WHITE AlienVault 2026-04-29 Modified: 2026-04-29
12
IOCs
MEDIUM VOLUME
A detailed technical analysis confirms that Kyber ransomware implements genuine hybrid post-quantum cryptography rather than mere branding. The Rust-based Windows variant encrypts files using AES-256-CTR with Kyber1024 and X25519 for key protection, appending a fixed 0x744-byte trailer containing encrypted metadata. Instrumented analysis validated the cryptographic implementation through fixture decryption but found no practical recovery path from the sample alone. The encryptor targets multiple file types, deploys standard recovery-inhibition techniques, and marks encrypted files with a .#~~~ extension. A separate ESXi variant was found to use different cryptography despite similar branding. As of April 2026, one victim was publicly listed: a large American defense contractor and IT services provider.
Indicators of Compromise (5 / 12 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 1b66614d63ce9f1b0b9f68464a93d826a3af7e08ccadcbc662f8444f0eaab6b9 2026-04-29
FileHash-SHA256 4ed176edb75ae2114cda8cfb3f83ac2ecdc4476fa1ef30ad8c81a54c0a223a29 2026-04-29
FileHash-SHA256 5a5f2bfea416f4b9ed4e6e45d82df524c1d9fa5f99c08944f2bacdf5bf9f525d 2026-04-29
FileHash-SHA256 ef054d22823758290db94aab3c901471a9ebd633f94963030806cc68dd433d8d 2026-04-29
FileHash-SHA256 fcca04669f1a9c79786e29914563c772584fba1aebc58ce1fd17c8e11a1266ea 2026-04-29