Also known as: tracked as, drones, Bjorka, SkyWave, quic, Colddraw Ransomware, built a, OffSec, Lolkek, medium-sized, medium-sized bu, targeting nume, Dispossessor, active since August 2023, RA World, Raznatovic, Linux VMware, 54BB47h, Fonix, Abyss Locker, ARCrypter, GlobeImposter, CosmicBeetle, PlayCrypt, N13V, operated by UNC2190, FonixCrypter
Gammax operates as a ransomware-as-a-service (RaaS) provider offering victims both file encryption and a dedicated leak site hosted on a Tor hidden service. The organization’s playbook begins with initial access through spear‑phishing links or exploitation of Remote Desktop Services. Once inside, it deploys backdoor trojans that establish persistence and facilitate credential dumping. Following exfiltration of internal documents, Gammax launches custom ransomware variants—most notably those using unique encrypted file extensions such as .vanhelsing and .vanlocker—before demanding ransom payment. The group leverages AI‑based development techniques and reportedly incorporates children’s coding software in order to produce multimillion‑dollar payloads. Communication is conducted over the Tox peer‑to‑peer protocol, while leaked data is distributed across public broker sites such as DarkFeed and ransom.live. Gammax has claimed attacks on a diverse set of organizations, including MTCO (Saudi Arabia), RE/MAX 1st Choice (Florida), and AguAseo (Panama), highlighting an ability to penetrate corporate entities that hold valuable personal or commercial information. Gammax’s operations are characterized by rapid data exfiltration and public shaming tactics rather than mass data dumps, aligning with contemporary double‑extortion strategies used by other emerging ransomware actors. The actor demonstrates a moderate level of technical sophistication—evidenced by custom encryption schemes and AI integration—yet remains accessible as an RaaS to smaller threat actors. Overall, Gammax blends typical cybercriminal techniques with sophisticated development practices to maximize financial gain while exerting leverage through public data leaks, positioning it as a notable threat to mid‑size enterprises in several high‑risk industries.
Objectives
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Gammax is a medium‑sophistication ransomware-as-a-service collective that emerged in late 2025 and has aggressively targeted commercial and critical infrastructure entities across the Middle East, North America, and Europe. They employ a double‑extortion model—encrypting data while simultaneously leaking stolen files via a TOR‑hosted leak site or third‑party broker sites—to pressure victims into paying. The group’s rapid post‑exfiltration leak tactics, combined with AI‑driven development of custom payloads, have led to high‑impact breaches in the financial, healthcare, and energy sectors.
Goals & Targeting
The strategic objective of Gammax is purely financial: acquire ransom payments and monetise stolen data. The actor concentrates on corporate entities across finance‑services, healthcare, construction, manufacturing, transportation, government, energy, utilities, oil‑gas, hospitality, defense, critical infrastructure, education, telecommunications, and retail sectors. Victims are selected for the richness of personal or commercial records they hold—such as customer databases, financial ledgers, or proprietary designs—making data breach plus ransomware a two‑pronged incentive. The geographic spread—including Saudi Arabia, United States, Pakistan, Canada, Australia, Brazil, France, Israel, Iran, and Russia—suggests opportunistic targeting based on market attractiveness rather than clear geopolitical focus. In short, Gammax seeks to extort maximum value from entities that can pay quickly, leveraging both encryption pressure and reputational damage to compel payment.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Gammax first surfaced in late 2025, with its earliest confirmed attack reported against MTCO (Saudi Arabia) and subsequent incidents including RE/MAX 1st Choice (Florida) and AguAseo (Panama). The group appears to ramp up activity rapidly: initial infiltration, quick data exfiltration, encryption, and immediate leak of stolen files. Victims often fall within mid‑sized corporations that lack robust incident response capabilities. While the overall operational tempo is moderate—about a handful of attacks per month—the actor demonstrates consistent use of its double‑extortion framework across varied sectors and geographies. No confirmed attribution to any nation state has emerged, with publicly available evidence pointing toward a purely commercial cybercriminal operation. Future campaigns are likely to continue leveraging spear‑phishing emails or RDP exploits, aiming at data‑rich corporate clients and maintaining the release of exfiltrated files on public broker sites to pressure payment. Gammax’s infrastructure remains largely anonymous but is known to use fast‑flux DNS for leak sites and Tox P2P for C2. Overall, the group’s pattern reflects a professional ransomware operation that balances sophisticated malware development with opportunistic target selection to maximize financial return.
IOC Patterns
Recommended Actions
No observed data linked yet.
11
Techniques
49
Tools
4
Campaigns
39
IOCs
0
Observed Data
8
Tactics