Skip to main content

Operator dossier

cring is a ransomware operator no longer publishing new disclosures. Darkfield has indexed 1 public victims claimed by this operator between January 1, 2021. The Cring ransomware group emerged in January 2021 as a financially motivated cybercriminal organization targeting critical infrastructure sectors. The group is believed to operate independently with suspected origins linked to Russian-speaking threat actors, though definitive attribution remains unclear. Cring operators primarily gain initial access through exploitation of vulnerable internet-facing services and applications, subsequently deploying their custom ransomware payload that encrypts victim files while demanding cryptocurrency payments for decryption keys. The group has demonstrated a focus on critical manufacturing sectors, with documented activity primarily concentrated in Italy, suggesting either regional targeting preferences or opportunistic exploitation of vulnerable Italian infrastructure. Based on limited public reporting from security researchers, Cring appears to have had minimal operational impact with only one confirmed victim, and the group's current operational status remains unclear due to sparse intelligence reporting since their initial identification.

Most-targeted sectors

Most-affected countries

Recent disclosures by cring

All 1 indexed disclosures. Click any row for the full per-victim dossier.

See every disclosure indexed for cring

How we know this. Operator profiles on Darkfield are built from continuous monitoring of every leak site the group is known to operate, cross-correlated with community-curated feeds (RansomLook, ransomware.live, RansomWatch, MISP-galaxy). Status flips from active to inactive when no new disclosure appears for 60 days. MITRE ATT&CK mappings shown in the interactive section below are sourced from CISA, vendor analysis, and the MITRE community catalog — we attribute each technique back to its source. Aliases reflect operator re-brands and affiliate splits.

Inactive ransomware operator

All groups

cring

1 victims indexed · first seen 6 years ago · last activity 6 years ago

1
Victims indexed
#323 of 370 tracked operators
<1m
Active period
Jan 2021 → Jan 2021
1
Countries hit
top IT · 1

At a glance

Status
inactive
First seen
6 years ago
Last activity
6 years ago
Primary sector
Critical Manufacturing · 1 hits

About

The Cring ransomware group emerged in January 2021 as a financially motivated cybercriminal organization targeting critical infrastructure sectors. The group is believed to operate independently with suspected origins linked to Russian-speaking threat actors, though definitive attribution remains unclear. Cring operators primarily gain initial access through exploitation of vulnerable internet-facing services and applications, subsequently deploying their custom ransomware payload that encrypts victim files while demanding cryptocurrency payments for decryption keys. The group has demonstrated a focus on critical manufacturing sectors, with documented activity primarily concentrated in Italy, suggesting either regional targeting preferences or opportunistic exploitation of vulnerable Italian infrastructure. Based on limited public reporting from security researchers, Cring appears to have had minimal operational impact with only one confirmed victim, and the group's current operational status remains unclear due to sparse intelligence reporting since their initial identification.

Timeline

1 months
2021-01-01T00:00:00+00:00 · 1
2021-01-01T00:00:00+00:002021-01-01T00:00:00+00:00

Top countries

🇮🇹 Italy
1

Top sectors

Critical Manufacturing
1

MITRE ATT&CK

3 techniques · 3 tactics

Tactics

Initial AccessExecutionImpact

Techniques

  • T1190Exploit Public-Facing Application
  • T1059Command and Scripting Interpreter
  • T1486Data Encrypted for Impact

Recent victims

Loading…

Source

Updated 6 years ago

Data on this page is sourced from the group's own leak posts, cross-checked with public ransomware trackers (RansomLook, ransomware.live, RansomWatch), MITRE ATT&CK, and our own Tor and Telegram crawlers. This is a public observatory page — share freely.

Get alerted the next time cring posts a victim.

Add cring to your watchlist — Pro pings you within 5 minutes of any new cring leak-site post, Telegram callout, or affiliate-rebrand inference.