Ransomware needs a way in. Stolen credentials are the cheapest one.
black x Ransomware Group
Ransomware group profile
5Victims
Description
No description available for this group.
Threat Level & Status Breakdown
For black x · Based on incidents in selected period
3.6threat level
Claimed100.0%6
First seenOct 2025
Last seenAug 2026
Avg ransom—
Payment rate—
Recent activity
Monthly attack count for black x in the selected period
5Total attacks
3peak in Aug
1.7avg / month
↑ 2 vs first month
No intelligence data for this group.
TTPs & Attack Vectors
Tools, initial access, and MITRE ATT&CK techniques for black x
Credential Access
T1003
OS Credential Dumping
Defense Evasion
T1562
Impair Defenses
Execution
T1059
Command and Scripting Interpreter
Impact
T1486
Data Encrypted for Impact
T1490
Inhibit System Recovery
Lateral Movement
T1021
Remote Services
T1021.001
Remote Desktop Protocol
T1080
Taint Shared Content
Persistence
T1078
Valid Accounts
T1547
Boot or Logon Autostart Execution
Victims(10)
| Company | Country | Status | Discovered | |
|---|---|---|---|---|
| FE CREDIT | — | Data Leaked | about 5 hours ago | |
| i-one | — | Data Leaked | about 5 hours ago | |
| Private(Chat...) | — | Claimed | 5 days ago | |
| Malaysia | Claimed | about 1 month ago | ||
| Assarai | Yemen | Claimed | about 1 month ago | |
| Sana'a Center For Strategic Studies | Yemen | Claimed | about 1 month ago | |
| Private | — | Claimed | 3 months ago | |
| Daechang Solution | South Korea | Claimed | 3 months ago | |
| WJ 원진성형외과 | South Korea | Claimed | 3 months ago | |
| Community Resource Services | Philippines | Claimed | 3 months ago |
Claimed
3 months ago Affected countries(2)
Countries where this group has been reported to target or leak victims.