Ransomware Intelligence

m3rx

Ransomware group profile

26Victims
63Impact score

Description

m3rx is a newly identified ransomware group that emerged in late April 2026, recognized for its rapid operational activity and deployment of a Go-based encryptor. It utilizes a double extortion model, encrypting files and threatening to release stolen data if ransom payments are not made.

Key insights

  • Employs a double extortion model with both data encryption and threat of public release of stolen data.
  • Utilizes a Go-based PE32+ x64 encryptor that renames files with a .8hmlsewu extension.
  • Demands payment in Bitcoin after negotiation while leveraging sensitive data exposure to press victims.
  • Erases its own traces by self-deletion through PowerShell post-execution.
  • Targets diverse sectors and countries, impacting organizations globally.

Threat Level & Status Breakdown

For m3rx · Based on incidents in selected period

1.9threat level
Aggressiveness5/ 10
Lethality0/ 10
Criticality0.6/ 10

Status Breakdown

Claimed88.5%23
First seenApr 2026
Last seenJun 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedJun 18, 2026

Recent activity

Monthly attack count for m3rx in the selected period

26Total attacks
12peak in May
8.7avg / month
↓ 2 vs first month
AprMayJun036912

Intelligence

IOCs, YARA/Sigma rules, and related families for m3rx

  1. fa410423b2982a435bc488aa652a96c4fe65dad66313378ca7c14bec23697327
  2. 194086c3836c768a871d9998fccbed7ef73fcc5f3fbd541720b52205c774c735
  3. 34af56de4c2b7216ce832be471c791eb350248683cb91924eefdcfc67738f296
  4. 521b1bd3f30ca50eaee6f74718b97dbe8a49c245
  5. cdbe4aed37c98d67a005ef469e7e0586e0ff8973b91a8d577d320e67cf46b572
  6. fc18506bbbbe57fdcecaa424735705501480e6708b634457010a5cf6bdc42525
  7. 1c648500122bb140d0857c15e3af92a1a3f3084e9f7247c8c21fc406a384136f
  8. b09ece33ffe5efb1903526229595a8c74d983c731505bee09c2a005036c834b8
  9. 071e2e0087554d96bba6a4ab73d88cd0
  10. ce1a0de9338a3aeb622ebaf27d4b73def4fcdd203e684084b5da8280357c3b4f
View full IOC feed17 total

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for m3rx

Other

T1486

T1486

T1490

T1490

T1071.001

T1071.001

T1041

T1041

T1562

T1562

T1080

T1080

T1059

T1059

T1021.001

T1021.001

T1547

T1547

T1027

T1027

Victims(26)

CompanyDomainCountryIndustryStatusDiscovered
maringoodman.commaringoodman.comUS United StatesRetail & E-Commerce
Claimed
8 days ago
suppcenter.global / suppcentersa.comsuppcenter.globalAR ArgentinaProfessional Services
Claimed
8 days ago
hbexperts-conseils.cahbexperts-conseils.caCA CanadaProfessional Services
Claimed
8 days ago
werkstoff-service.dewerkstoff-service.deDE GermanyManufacturing
Claimed
8 days ago
fasadeconsult.nofasadeconsult.noNO NorwayProfessional Services
Claimed
8 days ago
ktwhs.comktwhs.comTW TaiwanTransportation
Claimed
8 days ago
jichasa.comjichasa.comMX MexicoTransportation
Claimed
23 days ago
dosocho.esdosocho.esES SpainRetail & E-Commerce
Claimed
about 1 month ago
soft-inc.comsoft-inc.comJP JapanTechnology
Claimed
about 1 month ago
psbsementi.itpsbsementi.itIT ItalyOther
Unknown
about 1 month ago
grupo55.comgrupo55.comES SpainFinancial Services
Claimed
about 1 month ago
pvdd.capvdd.caCA CanadaGovernment & Defense
Claimed
about 1 month ago
datasavior.comdatasavior.comUS United StatesTechnology
Claimed
about 1 month ago
kbtoys.com.aukbtoys.com.auAU AustraliaRetail & E-Commerce
Claimed
about 1 month ago
alge-stop.dkalge-stop.dkDK DenmarkRetail & E-Commerce
Claimed
about 1 month ago
emtco.comemtco.comUS United StatesManufacturing
Claimed
about 2 months ago
it-freitag.deit-freitag.deDE GermanyTechnology
Claimed
about 2 months ago
manateeair.commanateeair.comUS United StatesTransportation
Claimed
about 2 months ago
dmschweiz.chdmschweiz.chCH SwitzerlandTechnology
Claimed
about 2 months ago
anvilarts.org.ukanvilarts.org.ukGB United KingdomHospitality
Claimed
about 2 months ago

Page 1 of 2