Cry0 surfaced on our tracker this week with a single confirmed claim, targeting a US retail and e-commerce victim, and shows no operational history beyond that August 6 debut. The group is described in its own materials as a ransomware-as-a-service operation built on a Rust-based payload, with affiliate recruitment run through underground forums and a claimed 90/10 revenue split favoring affiliates. It also claims to use blockchain-based negotiation infrastructure, built on the Internet Computer Protocol, to complicate law enforcement takedown efforts, though this remains an unverified operational claim rather than an observed capability. With only one victim logged and no MITRE ATT&CK technique data yet catalogued, Cry0 currently reads as a newly launched or rebranded RaaS brand still in its opening claim cycle, with activity concentrated in the US retail sector so far.