Written by: DarkWebSonar Research Team

Introduction
Sinobi is among the most US-concentrated ransomware operators tracked by DarkWebSonar, yet its observable leak-site activity follows a bursty affiliate-driven cadence rather than sustained daily output. Since July 2025, DarkWebSonar has recorded 277 victim postings attributed to Sinobi's Tor-based leak infrastructure. Eighty percent of named victims are US-based organizations, with manufacturing and construction representing nearly one-third of industry-tagged postings. After a six-week pause following March 2026 activity, Sinobi published six new victims on May 5, 2026, signaling that dormancy on the leak site is a pause, not a shutdown.

Sinobi is a likely rebrand of Lynx ransomware, with infrastructure and binary overlap to the INC Ransom lineage. Affiliates have been observed leveraging compromised SonicWall SSL VPN credentials, including MSP-managed paths with excessive Active Directory privileges, before deploying double-extortion operations.
Key findings from DarkWebSonar telemetry (July 2025–June 2026):
- 277 ransomware victim postings observed; 100% categorized as ransomware.
- 80% of named victims in the United States (221 of 277); 19 countries total.
- Top industries: Manufacturing & Construction (29%), Healthcare & Pharma (14%), Technology & Telecom (6%).
- Peak ISO weeks: 2025-W51 (32 postings), 2025-W41 (28), 2025-W34 (23), 2026-W02 (22); May 5, 2026 re-emergence (6 postings in 2026-W19).
- DarkWebSonar risk score: 91 / 100 (High); activity classification: dormant (0 postings in last 30 days as of June 2026).
We treat leak-site listings as intelligence signals rather than standalone proof of every operational detail. That means separating what the actor claims from what can be corroborated through victim statements, data exposure, and follow-on reporting.
By the Numbers (DarkWebSonar Telemetry)
DarkWebSonar monitors Sinobi's Tor-based data leak site continuously. The 277 victim postings below reflect what the group chooses to publish; posting volume is a useful proxy for extortion activity and affiliate output, though it undercounts victims who pay quietly or are never listed.
- Total victim postings (Jul 2025–Jun 2026): 277 across 19 countries; United States victims represent 80% of named targets
- Recent momentum: 6 of 277 postings landed in the last 90 days (May 5, 2026 burst); 0 in the last 30 days
- DarkWebSonar risk score: 91 / 100 (High)
- Activity classification: dormant
- Primary network: Tor (99% of incidents)
Posting cadence and year-week analysis
When DarkWebSonar telemetry is aggregated by ISO year-week, Sinobi's activity divides into four observable phases:
- Emergence (Jul–Sep 2025): Low baseline with an early acceleration in 2025-W34 (23 postings), driven by 22 victims published on August 20, 2025.
- October surge (2025-W40–W44): Sustained affiliate output peaking in 2025-W41 (28 postings), including 18 victims on October 8, 2025.
- Holiday-period wave (2025-W51–2026-W04): December and January clusters totaling 32 postings in 2025-W51 alone (peaks of 12 on December 16 and 11 on December 18), followed by 22 postings in 2026-W02 (14 on January 5, 2026).
- Pause and re-emergence (Mar–May 2026): Seven postings across March 17–19, then six weeks of silence, followed by six postings on May 5, 2026 (2026-W19).

| Year-week | Victims posted | Notes |
|---|---|---|
| 2025-W51 | 32 | December surge (12 on Dec 16, 11 on Dec 18) |
| 2025-W41 | 28 | October affiliate wave (18 on Oct 8) |
| 2025-W34 | 23 | August acceleration (22 on Aug 20) |
| 2026-W02 | 22 | January wave (14 on Jan 5) |
| 2025-W40 | 18 | Early October buildup |
| 2026-W19 | 6 | May 5 re-emergence after six-week pause |
We assess that Sinobi's burst weeks reflect batch publication of victims compromised during preceding weeks, expanded affiliate output, or both. The May 2026 postings after a March close-out suggest retained affiliate capacity rather than operational retirement.
Targeting distribution
Sinobi's victim geography is heavily US-weighted with opportunistic secondary targeting abroad:

- United States (80%): 221 victims anchor the distribution.
- India (4%): 12 victims, the largest non-US concentration.
- Canada (3%): 7 victims.
- France and United Kingdom (2% each): 5 victims each.
- Additional victims across Europe, Latin America, the Middle East, and Asia-Pacific in single-digit counts.
Industry targeting concentrates in sectors where downtime creates immediate extortion leverage:

- Manufacturing & Construction: 80 (29%)
- Healthcare & Pharma: 38 (14%)
- Technology & Telecom: 18 (6%)
- Financial Services: 14 (5%)
- Retail & E-commerce: 12 (4%)
- Legal & Consulting: 12 (4%)
The manufacturing and healthcare concentration aligns with external reporting on Sinobi's mid-market US targeting, though DarkWebSonar's industry fields reflect leak-site metadata and may be incomplete.
Notable posting events
- Aug 20, 2025 (22 victims posted in a single day; largest daily batch in DarkWebSonar telemetry)
- Oct 8, 2025 (18 victims posted)
- Dec 16, 2025 (12 victims posted)
- Dec 18, 2025 (11 victims posted)
- Jan 5, 2026 (14 victims posted)
- Mar 17–19, 2026 (7 victims across three days; last activity before pause)
- May 5, 2026 (6 victims posted; re-emergence after six-week silence)
Tactics, Techniques & Procedures (TTPs)
Extortion strategy
Sinobi operates a ransomware-centric double-extortion model. All 277 DarkWebSonar incidents map to T1486 (Data Encrypted for Impact), T1027 (Obfuscated Files or Information), and T1490 (Inhibit System Recovery), consistent with encryption paired with backup disruption and leak-site pressure.

Affiliates publish victim names on Tor-based negotiation portals and apply data-exfiltration leverage before or alongside encryption. Public reporting notes .SINOBI file extensions and README.txt ransom notes left on affected systems.
Initial access and technical capabilities (open-source reporting)
DarkWebSonar visibility begins at the leak site; initial access and encryptor details below come from public reporting.
Sinobi affiliates gain entry through compromised SonicWall SSL VPN credentials (including third-party MSP-managed accounts), exploitation of SonicWall vulnerabilities, and phishing. Documented post-compromise behavior includes local administrator account creation, EDR impairment (e.g., VMware Carbon Black), RDP lateral movement, and data exfiltration via RClone or WinSCP before ransomware deployment. Encryptors use Curve-25519 and AES-128-CTR; volume shadow copies and Recycle Bin clearing inhibit recovery.
DarkWebSonar's profile associates Sinobi with a broader known-technique set spanning initial access (T1190, T1566), credential abuse (T1078, T1021.001), discovery (T1083, T1087.002), defense evasion (T1562.001, T1070.004), and exfiltration (T1567.002), though per-incident MITRE mapping in DWS is limited to the encryption core above.
External analysis reports substantial binary similarity between Sinobi and Lynx samples (~63% function overlap), supporting the assessed INC/Lynx lineage rather than a wholly independent codebase.
Business model
Sinobi operates as a Ransomware-as-a-Service platform with affiliate-driven victim publication. Leak-site design and infrastructure overlap with Lynx reporting is consistent with a rebrand or shared operator cluster rather than a net-new ecosystem, per external assessments.
Evolution & Trends
Sinobi's operational timeline in DarkWebSonar telemetry aligns with external reporting on rapid RaaS emergence and Lynx lineage:
- June–July 2025: First observed leak-site activity; public reporting places initial operations in late June 2025.
- August 2025: First major acceleration (2025-W34, 23 postings; 22 on August 20).
- October 2025: Sustained affiliate surge (2025-W41, 28 postings) documented in DarkWebSonar's original Sinobi profile.
- December 2025–January 2026: Holiday-period wave (2025-W51 peak of 32; 2026-W02 peak of 22).
- February–March 2026: Declining but persistent output (18 postings in February; 7 in mid-March).
- May 2026: Six-posting re-emergence on May 5 after six weeks of silence; last observed activity in DarkWebSonar telemetry.
We assess that Sinobi followed a classic RaaS maturation arc: rapid affiliate onboarding, burst publication cycles, a mid-2026 slowdown, and a brief May reactivation. Dormant classification in June 2026 does not eliminate reactivation risk if affiliates retain tooling and access broker relationships.
Notable Campaigns / Victims

External reporting documents sector-relevant Sinobi intrusions rather than a single monolithic campaign:
- MSP-mediated SonicWall VPN compromise (August 2025): An affiliate used compromised third-party MSP SonicWall SSL VPN credentials mapped to domain administrator rights, RClone exfiltration, and Sinobi encryption across local and network drives.
- SonicWall exploitation wave (Q3–Q4 2025): Multiple reports correlated Sinobi activity with SonicWall SSL VPN flaws, including CVE-2024-40766 and CVE-2024-53704.
- US industrial and healthcare targeting: Sector analysis identified construction, manufacturing, and healthcare as primary victim pools, consistent with DarkWebSonar's 29% manufacturing and 14% healthcare concentrations at 277-incident scale.
DarkWebSonar treats these listings and reported cases as intelligence signals; corroboration requires victim disclosure, forensic evidence, or regulatory filings beyond leak-site metadata alone.
DarkWebSonar Insights
- Burst-week detection identified the August 20, 2025 single-day surge (22 postings) and the December 2025 cluster (32 postings in 2025-W51) while quarterly summaries still cited lower totals from earlier snapshots.
- US concentration surfaced an 80% country share at 277-incident scale, sharper than many globally distributed RaaS operators and relevant for US-focused SOCs weighting threats by domestic victim volume.
- Manufacturing skew showed 29% industry concentration, a signal that distinguishes Sinobi from groups with broader professional-services weighting.
- May re-emergence tracking captured six new postings on May 5, 2026 after a six-week pause, indicating retained affiliate activity that static "last seen March" assessments would have missed.
Defender Outlook 2026
Persistent risk: Organizations in Manufacturing & Construction, Healthcare & Pharma, Technology & Telecom, and Financial Services should treat Sinobi as an active RaaS threat despite current dormancy. The 80% US share defines the primary hunting ground, but India, Canada, and Western Europe show recurring victim counts.
Tempo: Sinobi's output arrives in ISO-week bursts (2025-W34, 2025-W41, 2025-W51, 2026-W02) with episodic reactivation (2026-W19). Detection readiness matters more than calendar-based monitoring windows; a six-week pause followed by six postings in one day illustrates how quickly leak-site activity can resume.
Defensive actions:
- Patch and harden SonicWall appliances; validate Gen 6 to Gen 7 migration credential risks tied to CVE-2024-40766.
- Enforce phishing-resistant MFA on VPN, RDP, and MSP-managed remote access; eliminate domain-administrator rights on VPN accounts.
- Monitor for RClone, WinSCP, and unusual cloud sync activity preceding encryption events.
- Alert on local administrator creation and clustered EDR process termination.
- Maintain immutable, segmented backups; recovery inhibition (T1490) is inherent to Sinobi's ransomware model.
- Establish early warning for organizational exposure on leak sites (DarkWebSonar provides continuous leak-site monitoring).
No public law enforcement takedown targeting Sinobi has been identified as of June 2026.
Threat Intelligence Indicators
Key vulnerabilities exploited
DarkWebSonar CVE associations in Sinobi's profile:
- CVE-2024-40766 (SonicOS improper access control)
- CVE-2024-53704 (SonicWall SSL VPN authentication bypass)
- CVE-2025-61882 (Oracle E-Business Suite)
Attack progression timeline
- Initial compromise via compromised SonicWall VPN credentials, vulnerability exploitation, or phishing
- Privilege escalation and lateral movement (RDP, local administrator creation)
- EDR impairment and discovery across file shares
- Data exfiltration via RClone or WinSCP
- Ransomware deployment with
.SINOBIextensions and ransom note delivery - Leak-site posting and Tor-based negotiation
Conclusion
Sinobi scaled from a mid-2025 emergence to 277 leak-site postings in under a year, with an 80% US victim concentration and a manufacturing-heavy industry profile uncommon at this volume. The group's burst-publication cadence, Lynx lineage, and May 2026 re-emergence after a March pause make dormancy an unreliable indicator of retirement.
For defenders, the practical implication is that Sinobi's access patterns are consistent and addressable: exposed SonicWall VPN infrastructure without enforced MFA, over-privileged remote access accounts (especially MSP-managed), and insufficient backup isolation. Closing those gaps, combined with leak-site early warning, is the highest-value control stack against this group.
Data notes: Statistics in this profile are derived from DarkWebSonar telemetry on Sinobi's Tor leak site unless attributed to open-source reporting. Posting dates may lag compromise; batch publication can inflate single-week counts. Country and industry fields reflect leak-site metadata.
Dark Web Most Wanted profiles are powered by DarkWebSonar's continuous monitoring of ransomware leak sites. Want real-time visibility into groups like Sinobi? Contact Sales.