Triple X is a ransomware group that emerged in May 2026, specializing in the exfiltration of sensitive data to extort victims. They utilize a double-extortion model and maintain a leak site on the Tor network to publish stolen data, primarily targeting financial institutions and professional services.
Key insights
•Employs double-extortion tactics, threatening public release of stolen data.
•Targets primarily financial institutions and professional service firms.
•Gains initial access through brute force attacks on RDP services and exploitation of valid accounts.
•Uses command and scripting interpreters for movement within compromised networks.
•Impairs security tools and deletes backups to obstruct recovery efforts.