Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors gammax

Also known as: tracked as, drones, Bjorka, SkyWave, quic, Colddraw Ransomware, built a, OffSec, Lolkek, medium-sized, medium-sized bu, targeting nume, Dispossessor, active since August 2023, RA World, Raznatovic, Linux VMware, 54BB47h, Fonix, Abyss Locker, ARCrypter, GlobeImposter, CosmicBeetle, PlayCrypt, N13V, operated by UNC2190, FonixCrypter

Description

Gammax operates as a ransomware-as-a-service (RaaS) provider offering victims both file encryption and a dedicated leak site hosted on a Tor hidden service. The organization’s playbook begins with initial access through spear‑phishing links or exploitation of Remote Desktop Services. Once inside, it deploys backdoor trojans that establish persistence and facilitate credential dumping. Following exfiltration of internal documents, Gammax launches custom ransomware variants—most notably those using unique encrypted file extensions such as .vanhelsing and .vanlocker—before demanding ransom payment. The group leverages AI‑based development techniques and reportedly incorporates children’s coding software in order to produce multimillion‑dollar payloads. Communication is conducted over the Tox peer‑to‑peer protocol, while leaked data is distributed across public broker sites such as DarkFeed and ransom.live. Gammax has claimed attacks on a diverse set of organizations, including MTCO (Saudi Arabia), RE/MAX 1st Choice (Florida), and AguAseo (Panama), highlighting an ability to penetrate corporate entities that hold valuable personal or commercial information. Gammax’s operations are characterized by rapid data exfiltration and public shaming tactics rather than mass data dumps, aligning with contemporary double‑extortion strategies used by other emerging ransomware actors. The actor demonstrates a moderate level of technical sophistication—evidenced by custom encryption schemes and AI integration—yet remains accessible as an RaaS to smaller threat actors. Overall, Gammax blends typical cybercriminal techniques with sophisticated development practices to maximize financial gain while exerting leverage through public data leaks, positioning it as a notable threat to mid‑size enterprises in several high‑risk industries.

Goals & Targeting

Objectives

Ransomware
Financial Gain

Targeted Sectors

Financial services
Healthcare
Construction
Manufacturing
Transportation
Government
Energy
Utilities
Oil gas
Hospitality
Defense
Critical infrastructure
Education
Telecommunications
Retail
Information technology

Targeted Countries / Regions

SA
US
PK
CA
AU
BR
FR
IL
IR
RU

AI Analysis

Grounded in web research
· 1 day ago

Executive Summary

Gammax is a medium‑sophistication ransomware-as-a-service collective that emerged in late 2025 and has aggressively targeted commercial and critical infrastructure entities across the Middle East, North America, and Europe. They employ a double‑extortion model—encrypting data while simultaneously leaking stolen files via a TOR‑hosted leak site or third‑party broker sites—to pressure victims into paying. The group’s rapid post‑exfiltration leak tactics, combined with AI‑driven development of custom payloads, have led to high‑impact breaches in the financial, healthcare, and energy sectors.

Goals & Targeting

The strategic objective of Gammax is purely financial: acquire ransom payments and monetise stolen data. The actor concentrates on corporate entities across finance‑services, healthcare, construction, manufacturing, transportation, government, energy, utilities, oil‑gas, hospitality, defense, critical infrastructure, education, telecommunications, and retail sectors. Victims are selected for the richness of personal or commercial records they hold—such as customer databases, financial ledgers, or proprietary designs—making data breach plus ransomware a two‑pronged incentive. The geographic spread—including Saudi Arabia, United States, Pakistan, Canada, Australia, Brazil, France, Israel, Iran, and Russia—suggests opportunistic targeting based on market attractiveness rather than clear geopolitical focus. In short, Gammax seeks to extort maximum value from entities that can pay quickly, leveraging both encryption pressure and reputational damage to compel payment.

Enhanced Description

Key Capabilities

  • Spear‑phishing with malicious links
  • Exploitation of Remote Desktop Services for initial access
  • Deployment of backdoor trojans for persistence
  • Credential dumping via custom malware
  • Rapid data exfiltration scripts
  • Custom ransomware engine using unique file extensions (.vanhelsing, .vanlocker)
  • Double‑extortion leak sites on Tor hidden services
  • Use of Tox P2P protocol for command and control
  • AI‑driven development of malicious payloads
  • Dissemination of stolen datasets via public broker sites (DarkFeed, ransom.live)

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Credential Dumping
Defense Evasion
Collection
Exfiltration
Command and Control
Impact

ATT&CK Techniques

T1566.001
T1078
T1190
T1059.003
T1035
T1005
T1041
T1486
T1202
T1027
T1110

Software / Tooling

Gammax Ransomware
VanHelsing
AvosLocker
BlackCat
Avaddon
HELLOKITTY
Babuk
Cuba
Akira
LockBit 3.0
Netwalker
Royal
Qilin
Abyss Locker
Dove
PICKLE

Campaigns & Victims

Gammax first surfaced in late 2025, with its earliest confirmed attack reported against MTCO (Saudi Arabia) and subsequent incidents including RE/MAX 1st Choice (Florida) and AguAseo (Panama). The group appears to ramp up activity rapidly: initial infiltration, quick data exfiltration, encryption, and immediate leak of stolen files. Victims often fall within mid‑sized corporations that lack robust incident response capabilities. While the overall operational tempo is moderate—about a handful of attacks per month—the actor demonstrates consistent use of its double‑extortion framework across varied sectors and geographies. No confirmed attribution to any nation state has emerged, with publicly available evidence pointing toward a purely commercial cybercriminal operation. Future campaigns are likely to continue leveraging spear‑phishing emails or RDP exploits, aiming at data‑rich corporate clients and maintaining the release of exfiltrated files on public broker sites to pressure payment. Gammax’s infrastructure remains largely anonymous but is known to use fast‑flux DNS for leak sites and Tox P2P for C2. Overall, the group’s pattern reflects a professional ransomware operation that balances sophisticated malware development with opportunistic target selection to maximize financial return.

IOC Patterns

  • Spear‑phishing emails with malicious links
  • Exploitation of Remote Desktop Services vulnerabilities
  • Use of Tox peer‑to‑peer protocol for command and control

Recommended Actions

  • Deploy multi‑factor authentication on all remote desktop services and enforce strong, unique passwords.
  • Regularly patch known RDP CVEs (e.g., MS17‑010) and consider disabling or hardening RDP if not essential. "",
  • Implement email filtering and advanced threat protection to block spear‑phishing payloads.
  • Enable network monitoring and alerting for unusual outbound traffic patterns indicative of data exfiltration or connection to Tor/C2 nodes.
  • Maintain offline, immutable backups and test restoration procedures before encrypting data in situ.
  • Educate employees on phishing recognition and conduct regular security awareness training. "",
  • Apply strict least‑privilege policies and monitor privileged account usage for anomalies.
  • Use host‑based detection systems that flag unauthorized trojan persistence mechanisms. "
  • Set up a dedicated leak site monitoring service to receive early warnings of data exposures from broker sites like DarkFeed, ransom.live, etc.

Software / Tooling

Campaigns / Victims

Observed Data

No observed data linked yet.

References

Intel Summary

11

Techniques

49

Tools

4

Campaigns

39

IOCs

0

Observed Data

8

Tactics

Tags

ransomware
double‑extortion
data-breach
backdoor
AI-based malware
Leak Site
Tor hidden service
Leak site abuse
broker‑and‑dump ecosystem
Cryptocurrency Ransomware
Gammax
GCC region
Saudi Arabia
July 2026
August 2026

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Country of Origin
China (CN)
Confidence
80%
First Seen
Jul 3, 2026
Last Seen
Aug 6, 2026
Added
Jul 31, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.