Black X is a ransomware threat group active by at least 2026. Reporting places it among a broader set of emerging and mid-tier ransomware actors rather than the highest-volume major crews. The group has been linked to ransomware intrusions affecting organizations in multiple countries, including a reported victim in Yemen, and has also been identified among the actors associated with ransomware victimization in South Korea during Q2 2026. Available reporting on Black X is limited, and few distinctive tradecraft details are publicly corroborated at high confidence. What is established is that the group conducts ransomware operations and has been associated with data-breach activity in connection with those attacks. No reliable evidence in the available material supports attribution to a specific nation-state sponsor, operating country, or a broader cluster beyond the aliases Black X, blackx, and black_x. Given the currently available facts, Black X is best characterized as a financially motivated ransomware actor with confirmed victimization activity but insufficient public detail to confidently enumerate specific intrusion techniques, tooling, or extortion patterns such as double extortion or data-theft-only extortion.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a ransomware attack against the organization sanaa.
Named as one of the emerging/smaller ransomware groups contributing to diversification of ransomware activity in Korea; tied to multiple domestic victim cases in the quarter.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.