Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Weyhro

Weyhro is a data-extortion group (relying on data theft and leak threats without file encryption) that launched a Tor leak site in March 2025, focusing on manufacturing, financial services, and real estate sectors with victims in the US, Italy, and Canada.

Victims
14
 
First Discovered
2025-03-06
victim
Last Discovered
2025-08-11
victim
Inactive Since
279
days
Avg Delay
18
days
Infostealer
7.1%
victims with domain
Countries
5
hit
View Victims on World Map View Group Statistics
Attack Velocity — Last 12 months

Known Locations (3)
Favicon Title Type Available Last Visit Server Info FQDN
favicon No 2026-04-28T07:22:21 xtxtpqpyaaek4p4525ksepyyy75gfvi47fptm2gftw7cn656rnfhzdqd.onion
favicon weyhro.hk | 522: Connection timed out Yes 2026-05-17T07:43:25 cloudflare weyhro.hk
favicon Weyhro No 2026-04-28T07:24:57 weyhro27ruifvuqkk3hxzcrtxv2lsalntxgkv6q2j3znkhdqudz54rqd.onion

Target
Top 5 Activity Sectors
  • Manufacturing 5
  • Business Services 4
  • Financial Services 2
  • Public Sector 1
  • Technology 1
Top 5 Countries
  • US flag United States 10
  • BB flag Barbados 1
  • CA flag Canada 1
  • DE flag Germany 1
  • IT flag Italy 1

Heatmap

YARA Rules (1)

Indicators of Compromise (IoCs) (3)
IP Address 2 tox 1
Type IOC
IP Address 185.106.94.255
IP Address 194.87.85.168
tox 6CD290BA0876417B649DEA72CCD9E4052E40B53178521F1DB8844A29E6180F0AED874C9155C1

Victims (14)
Logo
Discovered: 2025-08-11 (9mo ago)  ·  Attack est.: 2025-08-10
[AI generated] Community Services of Missouri is an organization that provides a range of services t…
Logo
Discovered: 2025-08-11 (9mo ago)  ·  Attack est.: 2025-08-10
[AI generated] Chemtron RiverBend is a leading hazardous waste and non-hazardous waste management se…
Logo
Discovered: 2025-05-31 (11mo ago)  ·  Attack est.: 2025-05-26
[AI generated] Synergy Investments is a prominent real estate investment firm. Established in 1997, …
Logo
Discovered: 2025-05-31 (11mo ago)  ·  Attack est.: 2025-05-30
[AI generated] Terra Caribbean is a real estate services company based in the Caribbean. They provid…
Logo
Discovered: 2025-05-31 (11mo ago)
[AI generated] Adriatic Glass & Mirrors is a company based in Ontario, Canada. They specialize in pr…
Logo
Discovered: 2025-05-08 (1y ago)
[AI generated] N/A…
Logo
Discovered: 2025-03-31 (1y ago)
[AI generated] Valens Bank is a digital banking platform that offers private banking services to its…
Logo
Discovered: 2025-03-25 (1y ago)  ·  Attack est.: 2025-03-19
[AI generated] McMillan James Equipment Company (MJEC) specializes in providing end-to-end HVAC solu…
Logo
Discovered: 2025-03-25 (1y ago)  ·  Attack est.: 2025-03-21
[AI generated] Montgomery Little & Soran, PC is a full-service law firm based in Greenwood Village, …
Logo
Discovered: 2025-03-06 (1y ago)  ·  Attack est.: 2025-02-08
[AI generated] Central Electropolishing Company, Inc. (CELCO) is based in Arkansas, US. Since 1985, …
Logo
Discovered: 2025-03-06 (1y ago)  ·  Attack est.: 2024-12-12
[AI generated] Resnick & Caffrey, PC is a law firm that specializes in several areas of practice inc…
Logo
Discovered: 2025-03-06 (1y ago)  ·  Attack est.: 2025-02-22
[AI generated] Avantune Corporation is a technology company that specializes in self-service softwar…
Logo
Discovered: 2025-03-06 (1y ago)  ·  Attack est.: 2025-01-15
[AI generated] MBI International, Inc. is a private investment firm based in the United States. It s…
Logo
Discovered: 2025-03-06 (1y ago)  ·  Attack est.: 2025-02-26
[AI generated] Fragola S.p.A is an Italian company well-known in the field of fluid power transmissi…