BravoX is an emerging ransomware-as-a-service (RaaS) operation publicly observed since January 2026. The group uses a double-extortion model, stealing data before encrypting systems and threatening public release through a leak site and negotiation portal if victims do not pay. Reported victims span multiple countries and sectors, including organizations in Switzerland, the United States, Brazil, Italy, France, Canada, and the United Kingdom. Observed BravoX tradecraft includes initial access via externally exposed remote access infrastructure using weak credentials and absent multi-factor authentication; internal reconnaissance with network scanning and system discovery utilities; credential theft through LSASS memory dumping; and lateral movement via Remote Desktop Protocol. Persistence has been established through scheduled tasks that launched covert remote-access mechanisms, including Tor hidden-service exposure of RDP and an SSH-based SOCKS5 tunnel. Defense evasion has included attempts to disable endpoint protections and the use of an EDR-killing tool together with a vulnerable driver, consistent with BYOVD techniques. Data exfiltration has been conducted with Rclone prior to ransomware deployment. BravoX has encrypted both virtual and physical systems, including virtualization storage files, and has operated a structured extortion workflow with staged leak publication. When negotiations fail, the group has escalated pressure through aggressive harassment tactics such as mail bombing and contacting employees on professional networking platforms. Behavioral indicators and the group’s stated prohibition on targeting CIS organizations have led to assessments that it likely operates from the former Soviet sphere, but a specific country attribution is not established with high confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
22 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
13 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a ransomware attack against Moores, a UK-based kitchen solutions provider serving housing developers.
Conducting a ransomware attack against Elettrica System.
Conducting a ransomware attack resulting in a data breach against Verona 83.
Conducting a ransomware attack against MEDICOS, a France-based organization.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.