Gammax is a newly emerged extortion and crypto-ransomware operation that began in July 2026, focusing on commercial enterprises and utilities. The group employs a double-extortion model by exfiltrating sensitive data before encrypting files, using a dedicated dark web leak site to compel ransom payments from victims.
Key insights
•Targets small-to-medium businesses and utilities primarily for financial gain.
•Utilizes a double-extortion model, threatening public release of exfiltrated data if ransoms are not paid.
•Gains initial access through targeted phishing, weak RDP exploits, and leaked credentials.
•Employs rapid data exfiltration tactics to pressure victims into paying ransoms.
•Caches communications via Tor for anonymity and conducts attacks with obfuscated malicious scripts.