BravoX is a ransomware-as-a-service (RaaS) operation publicly identified in January 2026. It conducts financially motivated double-extortion operations, exfiltrating data before encrypting victim systems and threatening publication through a leak site. Its extortion platform uses staged publication, and the group has escalated unsuccessful negotiations through mail bombing and outreach to victim employees on LinkedIn. Observed BravoX intrusions have begun with exploitation of weak credentials on SSL VPN services lacking multi-factor authentication. The operators conduct internal reconnaissance, search for credentials and access information, dump LSASS memory to obtain credentials, and use RDP for lateral movement, including access to domain controllers. They have established persistence using scheduled tasks to deploy Tor-based remote access and SSH/SOCKS proxy tunneling. Defense evasion has included attempts to disable endpoint protection and use of an EDR-killer tool with a vulnerable driver. Data exfiltration has been conducted with Rclone, followed by encryption of physical systems and virtual-machine storage. BravoX has claimed victims in the United States, Switzerland, Brazil, Italy, Canada, France, and the United Kingdom. Confirmed victim organizations span industrial engineering, energy and utilities, health care, financial services, information technology, food and beverage distribution, construction and real estate, and logistics-related services. The group reportedly avoids targeting organizations in CIS countries, but its geographic origin has not been established with sufficient confidence to assign a country.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
22 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
13 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducted a ransomware attack against SCHMIDT, a US-based provider of abrasive blasting systems and engineering solutions.
Conducting a ransomware attack against Moores, a UK-based kitchen solutions provider serving housing developers.
Conducting a ransomware attack against Elettrica System.
Conducting a ransomware attack resulting in a data breach against Verona 83.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.