Also known as: triplex, tracked as, Triple X syndrome, Agent Triple X, played by Roger Moore, Jul 6, 2026, Mirage Kitten, Smoke Sandstorm, NightLedger, BridgeHead, ArcBridge, to maintain covert acces, abusing the trust, downloade, UNC1549
Triple X (also known as Triplex, Agent Triple X, Mirage Kitten, among other aliases) first appeared in public reports in May 2026 after a high‑profile incident at Bank of Baroda in India that released 100,000 to 300,000 account‑opening forms containing national IDs, photographs and financial details. The group’s documented playbook involves initial access via weak or reused credentials—often delivered through spearphishing attachments—and a subsequent multi‑stage exfiltration of sensitive PII and customer data. Post‑exfiltration, Triple X leverages a dark‑web leak site to publish proof of compromise and imposes a double‑extortion pressure: the data will be released unless the victim pays a ransom that covers both data restoration (if any) and a fee for non‑release. While public evidence currently lacks confirmation of classic file encryption, several incidents have reportedly involved partial or full encryption (e.g., the claim of data being locked in some Bank of Baroda accounts), underscoring their dual financial motive. The gang’s operational footprint extends across multiple continents—India, Indonesia, USA, Russia, Iran, Ukraine and numerous European and Middle‑East states—suggesting that they are exploiting broadly available remote access vectors (SMB, RDP) and open‑source scripts written in PowerShell or Node.js. Their use of public forums and underground marketplaces to trade leaked data points to a business‑oriented approach rather than a purely state‑sponsored espionage model. Key indicators from their observed TTPs include spearphishing email attachments, brute‑force password attacks on remote services, persistence via registry run keys, remote service C2 through HTTP(S) and SMB exfiltration tunnels, and reflective code loading to bypass memory‑based detections. The group also appears to employ financial theft techniques (T1657) for direct monetary extraction from compromised systems.
Objectives
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Triple X is an emerging double‑extortion ransomware group that surfaced in May 2026 and has already claimed victims across the financial, legal, healthcare, and telecommunications sectors in India, Indonesia, the United States and other countries. The gang publicly leaks exfiltrated data to pressure victims into paying ransoms, using a mix of spearphishing, credential abuse and web‑based C2 channels. Their attacks emphasize large volumes of personally identifiable information rather than purely encrypted files, indicating a data monetisation focus.
Goals & Targeting
Triple X’s strategic objectives are dual: immediate ransomware payments and long‑term revenue through data monetisation. By targeting high‑value sectors such as banking, legal services and healthcare—where customers hold large volumes of sensitive personal and financial information—they maximise both the threat of loss and the leverage for extortion. Victims are typically midsized organizations with limited zero‑trust controls; the group prefers those that rely on legacy authentication mechanisms or have a history of credential reuse. Their broad geographic reach reflects an opportunistic approach: they exploit shared supply‑chain weaknesses, universal phishing tactics, and cloud or on‑prem SMB services accessible from any region.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Triple X’s operations, first publicised in May 2026, have quickly evolved from isolated incidents to a coordinated campaign featuring over 4.5 TB of exfiltrated PII across three countries by mid‑2026. Their modus operandi involves gaining initial foothold through phishing or credential reuse, extracting data while stealthily persisting within the environment, and then leveraging an underground leak site to amplify pressure on victims. Unlike older ransomware groups that focused solely on encryption, Triple X’s hybrid model emphasises “double‑extortion”—the threat of publicising stolen data alongside a ransom demand—to maximise revenue streams. The rapid spread across diverse industries indicates either reuse of a common supply‑chain compromise or the leveraging of readily available open‑source infiltration tools.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The information presented is based primarily on publicly available incident reports and media statements dated May through August 2026. While the group’s name, basic tactics (phishing, credential abuse, exfiltration) are well‑documented, evidence of encryption-based attacks remains inconclusive, and many operational details rely on victim claims rather than forensic confirmation. Consequently, confidence is moderate for tactical attributes but lower concerning the existence of an actual ransomware engine versus a purely data‑thief approach. Additional technical verification and updated threat feeds would improve certainty.
No observed data linked yet.
37
Techniques
56
Tools
4
Campaigns
37
IOCs
0
Observed Data
15
Tactics