Ransomware Intelligence

bravox

Ransomware group profile

23Victims
GlobalSource country
42Impact score

Description

BravoX is an emerging ransomware group that surfaced in January 2026, operating as a Ransomware-as-a-Service (RaaS) and distinguished by its sophisticated double-extortion model. It seeks to exploit high-revenue targets while avoiding attacks within the CIS countries, reflecting common practices among Russian-speaking cybercriminals.

Key insights

  • Operates as a Ransomware-as-a-Service (RaaS) with an affiliate-driven model.
  • Initial access is often gained through compromised SSL VPNs with weak passwords and no multi-factor authentication.
  • Utilizes Rclone for large-scale data exfiltration and maintains sophisticated persistence mechanisms.
  • Imposes a double-extortion model, threatening data publication if ransom demands are not met.
  • Targets high-revenue sectors across various industries, with clear pressures applied through automated data leak site features.

Threat Level & Status Breakdown

For bravox · Based on incidents in selected period

3threat level
Aggressiveness7/ 10
Lethality0/ 10
Criticality1.7/ 10

Status Breakdown

Claimed91.3%21
First seenDec 2025
Last seenMay 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedJun 2, 2026

Recent activity

Monthly attack count for bravox in the selected period

23Total attacks
7peak in Feb
4.6avg / month
↑ 5 vs first month
DecFebMarAprMay02468

No intelligence data for this group.

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for bravox

Other

T1486

T1486

T1490

T1490

T1078

T1078

T1059

T1059

T1562

T1562

T1021.001

T1021.001

T1046

T1046

T1027

T1027

T1543

T1543

T1547

T1547

T1105

T1105

T1210

T1210

Victims(29)

CompanyDomainCountryIndustryStatusDiscovered
Grupo Mauágrupomaua.com.brBR BrazilManufacturing
Claimed
3 days ago
AcademyHealthacademyhealth.orgUS United StatesHealthcare
Claimed
5 days ago
Emek Elektrikemek.com.trTR TurkeyEnergy & Utilities
Claimed
11 days ago
Salvation Armysalvationarmy.caCA CanadaRetail & E-Commerce
Claimed
11 days ago
Rivadeneyra Treviñorivtrev.comMX MexicoProfessional Services
Claimed
23 days ago
Soproluxsoprolux.comFR FranceHospitality
Claimed
27 days ago
blogbravoxxwcfz5qk43ychgveprpd5mw5hvxfs4a2uz2okx7mumiht4fzyd.onion
Claimed
about 1 month ago
blogbravoxxwcfz5qk43ychgveprpd5mw5hvxfs4a2uz2okx7mumiht4fzyd.onion
Claimed
about 1 month ago
1st Solution CTC 🇩🇪DE GermanyProfessional Services
Claimed
about 1 month ago
blogbravoxxtrmqeeevhl7gdh2yzvlrjxajr66d33c7ozosrccx4cz7cepad.onion
Claimed
about 2 months ago
blogbravoxxtrmqeeevhl7gdh2yzvlrjxajr66d33c7ozosrccx4cz7cepad.onion
Claimed
about 2 months ago
Aculabaculab.comGB United KingdomTechnology
Claimed
about 2 months ago
UMBERG TREUHAND AGumberg-treuhand.chCH SwitzerlandFinancial Services
Claimed
3 months ago
VATIERFR FranceProfessional Services
Claimed
3 months ago
Sorecosoreco.chCH SwitzerlandProfessional Services
Claimed
3 months ago
OEC Bretagnebretagne.experts-comptables.frFR FranceFinancial Services
Claimed
4 months ago
SPEC 🇺🇸US United StatesTechnology
Unknown
4 months ago
FUSION HILL 🇺🇸US United StatesProfessional Services
Claimed
4 months ago
John O's Foods 🇨🇦CA CanadaRetail & E-Commerce
Claimed
4 months ago
jasper-avocats.comjasper-avocats.comFR FranceProfessional Services
Claimed
4 months ago

Page 1 of 2