Gammax is an emerging ransomware and data-theft extortion group active by mid-2026. It has been identified in leak-site reporting as a newly emerged actor that claimed attacks against numerous organizations. Reported victims include organizations in the United States, Saudi Arabia, and Colombia, indicating geographically diverse targeting. Observed victim sectors include professional services, wholesale and distribution, and utilities-related services. Reported incidents are described as ransomware attacks accompanied by data breaches, supporting assessment that the group uses extortion based on stolen data and likely operates a leak-site style disclosure model. High-confidence reporting supports Gammax’s role as a ransomware/extortion actor, but currently available information does not establish additional technical tradecraft, sub-groups, or a reliable attribution to any state sponsor or country of origin.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A newly emerged data theft/ransomware group reported as claiming attacks on numerous companies.
Conducting a ransomware attack against King International LLC, resulting in a data breach.
Conducting a ransomware attack against MTCO (Mahmoud Altaheni & Partners Trading Co) in Saudi Arabia.
Conducting a ransomware attack resulting in a data breach against MTCO in Saudi Arabia.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.