Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Cyble

Cyble Vendor Cyber Rating & Cyber Score

cyble.com

Cyble is the world’s first intelligence-driven, AI-native security platform that brings together detection, protection, and remediation across the entire digital attack surface. The company was born in Melbourne (Australia) and has since gone global, serving customers in more than 35 countries, with its headquarters now in Cupertino, California. Backed by Y Combinator and other leading venture capital firms, Cyble is on a mission to make the world a safer place by rethinking how cybersecurity works — through an AI-native platform built for predictive and autonomous defense. By combining deep intelligence, automation, and real-time response, Cyble helps organizations stay ahead of threats and build stronger, more resilient digital


Cyble A.I CyberSecurity Scoring

Cyble
Company Information
Website:https://cyble.com/
Employees number:250
Number of followers:83,862
NAICS:541514
Industry Type:Computer and Network Security
Homepage:cyble.com
Cyble Risk Score (AI oriented)
Between 600 and 649
logo
CybleComputer and Network Security
Updated:
03/04/2026
611/1000
Poor
Caa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Cyble Global Score (TPRM)
xxxx
logo
CybleComputer and Network Security
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Cyble
CyblePoor
Current Score
611Caa (POOR)
01000
3 incidents
-65 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
619Before Incident
MAY 2026
614Before Incident
APRIL 2026
614Before Incident
MARCH 2026
629Before Incident
Cyber Attack
05 Mar 2026Cyble
Cyble Research and Intelligence Labs: New Linux Threat ClipXDaemon Hijacks X11 Clipboard To Steal Crypto Transfers

ClipXDaemon Linux Malware Hijacks Crypto Wallet Addresses in X11 Sessions

609After Incident
LOW-20
CYB1773131064
New Linux Malware ClipXDaemon Hijacks Crypto Wallet Addresses in X11 Sessions A recently discovered Linux malware, ClipXDaemon, is targeting cryptocurrency users by silently replacing copied wallet addresses with attacker-controlled ones during transactions. Identified by Cyble Research and Intelligence Labs in early February 2026 and detailed on March 5, 2026, the malware exploits the common practice of copy-pasting wallet addresses, redirecting funds to threat actors without the victim’s knowledge. Unlike traditional malware, ClipXDaemon operates independently, eliminating the need for a command-and-control (C2) server. This makes it harder to detect, as it avoids network-based indicators of compromise. The malware is delivered via a loader using Bincrypter, an open-source shell-script encryption tool available on GitHub. While this technique was previously seen in ShadowHS campaigns, researchers found no direct link between the two threats only shared use of the same public tool. ClipXDaemon focuses solely on clipboard hijacking within X11 sessions, a widely used Linux windowing system. It monitors clipboard activity and replaces cryptocurrency wallet addresses in real time. Since many users rely on copy-paste for transactions, a single unnoticed alteration can result in funds being sent to the attacker instead of the intended recipient. The malware’s stealthy, self-contained design poses challenges for defenders, as traditional detection methods often rely on identifying suspicious outbound traffic or C2 communications. Its evolution reflects a broader trend in Linux malware toward targeted, profit-driven attacks that minimize detectable activity. Security recommendations include transitioning from X11 to Wayland (which ClipXDaemon avoids), monitoring for unusual clipboard polling, and verifying wallet addresses manually before transactions. The threat underscores the persistent risk of clipboard hijacking in cryptocurrency operations, even on less commonly targeted Linux systems.
INCIDENT DETAILS -
TYPE
Malware
MOTIVATION
Financial gain
IMPACT
Financial Loss: Funds redirected to attacker-controlled walletsSystems Affected: Linux systems using X11Operational Impact: Unauthorized fund transfersPayment Information Risk: Cryptocurrency wallet addresses
DATA BREACH
Type Of Data Compromised: Cryptocurrency wallet addressesSensitivity Of Data: High (financial)
FEBRUARY 2026
627Before Incident
JANUARY 2026
735Before Incident
Ransomware
13 Jan 2026Cyble
deVixor: New Android Banking Malware ‘DeVixor’ Adds Ransomware Capabilities

deVixor Android Banking Malware Campaign

625After Incident
CRITICAL-110
CYB1768350463
New Android Banking Malware "deVixor" Combines Ransomware with Credential Theft Cyble researchers have uncovered deVixor, a sophisticated Android remote access trojan (RAT) targeting Iranian banking users with a blend of credential theft, surveillance, and ransomware capabilities. First detected in October 2023, the malware spreads via phishing websites impersonating automotive businesses, luring victims into downloading malicious APK files. Originally focused on SMS harvesting, deVixor has rapidly evolved into a full-featured criminal platform. It now supports nearly 50 commands, including banking fraud, keylogging, ransomware deployment, and device surveillance. The malware leverages Firebase for command delivery and a Telegram-based bot infrastructure for scalable control, allowing attackers to evade detection while managing infections at scale. Key features include: - Credential theft: Harvests OTPs, banking credentials (via WebView-based JavaScript injection), and cryptocurrency exchange data. - Surveillance: Captures keystrokes, screenshots, contacts, and device notifications while blocking uninstallation. - Ransomware: Locks devices and demands TRON cryptocurrency payments, storing attack parameters in LockTouch.json to persist across reboots. Cyble’s analysis of over 700 samples confirms deVixor is an actively maintained criminal service, with its Telegram channel suggesting broader future targeting. The malware’s modular design and persistent updates highlight the growing sophistication of Android banking threats, blending traditional fraud with disruptive ransomware tactics.
INCIDENT DETAILS -
TYPE
Malware (Remote Access Trojan - RAT)
MOTIVATION
Financial abuse, credential theft, ransomware, device surveillance
IMPACT
Data Compromised: Banking credentials, OTPs, account balances, card numbers, messages from banks/cryptocurrency exchanges, contacts, keystrokes, screenshots, device notifications, personally identifiable information (PII)Systems Affected: Android devicesOperational Impact: Device locking via ransomware, unauthorized surveillance, credential theftIdentity Theft Risk: HighPayment Information Risk: High
DATA BREACH
Banking credentialsOTPsAccount balancesCard numbersMessages from banks/cryptocurrency exchangesContactsKeystrokesScreenshotsDevice notificationsPersonally Identifiable Information (PII)Sensitivity Of Data: HighData Exfiltration: Yes (sent to C&C server)Data Encryption: Yes (ransomware module encrypts device data)Personally Identifiable Information: Yes
DECEMBER 2025
735Before Incident
NOVEMBER 2025
734Before Incident
OCTOBER 2025
737Before Incident
SEPTEMBER 2025
737Before Incident
AUGUST 2025
737Before Incident
JULY 2025
736Before Incident
NOVEMBER 2020
754Before Incident
Data Leak
01 Nov 2020Cyble
Cyble Inc.

Data Breach at Cyble E-commerce Firm

693After Incident
CRITICAL-61
CYB34529523
The Criminal Investigation Department (CID) and the Cyber Crime Police are searching for the hacker who gained access to private information belonging to the e-commerce firm Cyble and posted advertisements for the sale of the data on the dark web. According to reports, the hacker sought payment from the business owner in order to remove the list. The issue was discovered after Praveen B.S., the business's owner, discovered that his client list had been taken. The data included details of all the customers who bought groceries and other products from his company’s online website, said a police officer.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Financial Gain
IMPACT
Data Compromised: Customer Details
DATA BREACH
Type Of Data Compromised: Customer DetailsSensitivity Of Data: High

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Cyble ?
?
What was Cyble's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Cyble's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Cyble's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Cyble's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Cyble's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Cyble's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Cyble's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Cyble's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Cyble's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Cyble's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Cyble's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Cyble's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Cyble ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Cyble's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?