Exitium is a data extortion group first observed in early 2026, operating a Tor-based double extortion site and targeting victims via bulk data exfiltration followed by public naming-and-shaming, with known victims including a Brazilian agro-industrial firm and a US county appraisal district. Known victims: 4 1 ransom note(s) on file
Objectives
Executive Summary
Exitium is a medium-sophistication criminal threat actor specializing in ransomware and data extortion activities. Operating since March 2026, Exitium has emerged as a significant player in the cybercrime landscape, leveraging Tor-based communication channels and double extortion tactics to target organizations across various sectors.
Goals & Targeting
Exitium's strategic objectives are centered around financial gain through ransomware campaigns and data extortion. The group appears to target sectors with significant data sensitivity or critical infrastructure, such as agro-industrial firms and public sector entities, which may have limited cybersecurity defenses or higher incentives to avoid publicity. Exitium's targeting profile suggests a focus on organizations that could be pressured into paying ransoms without drawing excessive attention from law enforcement.
Enhanced Description
Exitium is a newly identified cybercriminal group that has gained notoriety through its use of a Tor-based platform for double extortion. The group's primary modus operandi involves unauthorized access to victim networks, followed by the exfiltration of sensitive data and encryption of systems, demanding ransom payments for decryption keys while simultaneously threatening to publicly expose stolen information. Exitium has targeted both private sector entities and public organizations, with confirmed victims including a Brazilian agro-industrial firm and a U.S. county appraisal district. The group's operational approach combines technical proficiency with psychological tactics to pressure victims into paying ransoms, making them a growing concern for cybersecurity professionals.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Exitium's campaigns exhibit a targeted approach, typically selecting victims based on sectoral vulnerability and potential for financial gain. The group has demonstrated a rapid operational tempo, with multiple campaigns launched within the first month of observed activity. Notable operations include attacks against agro-industrial firms in Latin America and public sector entities in the U.S., highlighting their ability to pivot between different target types
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence inExitium's operational details is moderate due to limited historical data, as the group was first observed in early 2026. While their targeting patterns and tactics are well-documented based on available victim data, additional context such as specific toolsets or long-term campaign behavior remains unclear. Further analysis of their infrastructure and TTPs could provide deeper insights into Exitium's capabilities.
No techniques linked yet.
No tools linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
4
Campaigns
0
IOCs
0
Observed Data
0
Tactics