Quick Summary
AllegedExecutive Summary
UB Freight, a company operating in the transportation and logistics sector, has been identified as a victim on the dark web portal of the M3rx ransomware group. This listing, published on July 22, 2026, was discovered by SOCRadar’s Dark Web Monitoring service. The nature of UB Freight’s business, which involves interconnected shipping platforms and third-party financial systems, inherently increases its attack surface and potential exposure. This listing represents one of a comparatively small number of victims attributed to M3rx to date. Analysis of M3rx’s recent activities reveals that over the 60 days preceding this listing, the group claimed six other victims. Their targeting pattern has notably favored industries such as business services, transportation and logistics, and consumer services. The ransomware group primarily targets organizations located in the United States, Ireland, and Argentina. Similar to UB Freight, other recent victims such as WRT World Enterprises, FORECON Inc., Eclective, and Marin/Goodman LLP fall within the business services and logistics-related segments that M3rx frequently targets. Consequently, UB Freight aligns with the group’s established predilection for the transportation sector, even within M3rx’s otherwise varied and limited victimology.
Technical Analysis
SOCRadar’s analysis of stealer-log telemetry for the ubfreight.com domain revealed two records containing corporate usernames. These records were associated with a logistics portal, specifically a shipping-management subdomain, categorized as a customer or supplier account. The second record stemmed from a third-party financial platform, accessed via a corporate email address, which is a common indicator of workstation compromise. These findings suggest potential credential exposure, with log dates ranging from mid-2025 to June 2026. However, the limited sample size of two records makes it impossible to confirm persistent access or the specific methods used for compromise. The observed stealer-log data does not include any corporate identity provider or VPN endpoints. The dominant profile noted in the telemetry is “Mixed.” It is important to note that the absence of evidence in this specific queried sample does not guarantee that UB Freight is unaffected. The limited nature of the stealer-log data, as well as the possibility of credentials existing under alternate corporate domains or using personal email aliases, means further investigation is recommended. For ransomware groups like M3rx, harvested credentials from infostealers are a known pathway for initial access. Threat actors may source these credentials from underground marketplaces, validate them, and subsequently use them to gain entry into systems via Microsoft 365, VPNs, or remote-access portals before deploying ransomware. While this telemetry does not confirm M3rx specifically utilized these credentials, the documented exposure of a corporate account on a financial platform is consistent with the typical attack chains observed in similar incidents. This underscores the importance of immediate credential hygiene measures, including password rotation and prioritizing workstation triage within the affected organization. Further monitoring, including continued dark web and stealer-log surveillance, proactive credential checks, and reviewing access logs for Microsoft 365, VPN, and remote-access portals, is advisable.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.