Skip to content
CTI Academy Sponsor CTI Academy
Ransomware group

Weyhro ransomware

14 victims listed on the Weyhro leak site across 5 countries. Most recent disclosure .

Victims
14
0.1% of all tracked
Countries
5
Most: United States
Sectors
5
Most: Manufacturing
First seen
Mar 2025
In this database

ThreatAI analysis

Compiled from the ransomware.live profile for Weyhro and from this database. Figures and technique mappings are quoted from the source data, not inferred.

Data-extortion group Weyhro, responsible for theft without encryption targeting manufacturing, financial services, and real estate sectors in 14 victims across five countries, including the US, Italy, and Canada.

Who Weyhro is

Weyhro is a data-extortion group (relying on data theft and leak threats without file encryption) that launched a Tor leak site in March 2025, focusing on manufacturing, financial services, and real estate sectors with victims in the US, Italy, and Canada.

Recorded activity

Disclosures attributed to Weyhro in this database run from March 2025 to August 2025, totalling 14 victims — 0.1% of everything tracked here. Weyhro has listed victims in 5 countries in this database, most often United States, followed by Italy and Germany. The sectors appearing most in its listings are Manufacturing, Business Services, Financial Services.

Indicators of compromise

  • 194.87.85.168
  • 185.106.94.255

Showing a sample of 2 IP on file. Hashes and network indicators published for Weyhro. Leak-site addresses are deliberately excluded. Indicators age quickly — treat a match as a starting point for investigation, and an absence of matches as no assurance.

YARA detection rules

weyhro.yar
/*
weyhro ransomware
*/

rule weyhro_Ransomnote
{
    meta:
        author = "ransomware.live"
        family = "ransomware.weyhro"
        description = "Detects weyhro ransomware ransom note or artifact"
        date = "2026-05-04"
        severity = 7
        score = 70

    strings:
        $name1 = "weyhro" ascii nocase
        $name2 = "WEYHRO" ascii
        $onion  = "weyhro.onion" ascii nocase

    condition:
        any of them
}

Community-contributed rules for Weyhro, reproduced as published. Test them against your own corpus before relying on them: rule quality and false-positive behaviour vary by author.

Threat actor analysis

Weyhro has disclosed 14 victims on its leak site, 0.1% of all ransomware listings tracked in this database. Its earliest disclosure here dates to March 2025.

The group has listed organisations in 5 countries, most often in United States (10 victims), followed by Italy, Germany, Canada.

By industry, its listings concentrate in Manufacturing, Business Services, Financial Services — sectors that hold sensitive data or cannot tolerate long outages, both of which raise the pressure to pay.

Like most current ransomware operations, Weyhro is likely to use double extortion: data is stolen before files are encrypted, and organisations that refuse to pay are named on the leak site with the stolen data as leverage.

Weyhro victims 14

Organization Disclosed
Chemtron RiverBend
USUnited States
Community Services of Missouri
USUnited States
Adriatic Glass & Mirrors
CACanada
Synergy Investments
USUnited States
Terra Caribbean
BBBarbados
101 Arch Street
USUnited States
Valens Bank/Pay/Exchange
DEGermany
McMillan James Equipment Company (MJEC)
USUnited States
Montgomery Little & Soran, PC
USUnited States
Avantune Corporation
USUnited States
Central Electropolishing Company, Inc.
USUnited States
Fragola S.p.A
ITItaly
MBI International, Inc.
USUnited States
Resnick & Caffrey, PC
USUnited States

Frequently asked questions

What is Weyhro ransomware?

Weyhro is a ransomware threat group that has claimed 14 victims since its first known activity in March 2025. The group operates by infiltrating target networks, exfiltrating data, encrypting files, and threatening to publish stolen data on a dark web leak site if the ransom is not paid.

How many victims has Weyhro attacked?

Weyhro has claimed 14 victims in our database, representing 0.1% of all tracked ransomware attacks. The most targeted countries are United States, Italy, Germany, Canada.

Which countries does Weyhro target?

Weyhro has attacked organizations in 5 countries. The top targeted countries are: United States, Italy, Germany, Canada.

Which industries does Weyhro target?

Weyhro most frequently targets the Manufacturing, Business Services, Financial Services sectors based on victim disclosures in our database.

Is Weyhro still active?

Weyhro's most recent victim disclosure in our database was on August 11, 2025. Ransomware groups frequently rebrand or go dormant; monitor this page and our ransomware map for the latest activity.