
Inside Triple X: A New Ransomware Group Targeting Banks and Law Firms
Executive Summary :
Triple X is a financially motivated data-extortion group first observed in May 2026, with three claimed victims (India, Indonesia, US) across financial services and legal sectors, totaling over 4.5 TB of claimed data. The most severe incident, disclosed July 24, 2026, targeted Bank of Baroda, with claims of 100,000–300,000 leaked account-opening forms containing national IDs, photos, and financial data. The group runs a dark-web leak site and free-data extortion model, publicly posting samples to pressure victims. No publicly available evidence currently confirms the malware, initial access vector, or encryption methodology used by the group. Its TTP profile remains provisional.
Threat Actor Overview :
|
Field |
Details |
|
Threat Name |
Triple X (also referenced as "TripleX") |
|
Threat Type |
Data Extortion / Ransomware Group (data broker–style operation; leak site–based free-data extortion) |
|
Motivation |
Financial gain-monetizes stolen data via public leak-site posts, direct sale/PM negotiation on forums, and reputational pressure on victims |
|
First Observed |
Mid-to-late May 2026 |
|
Status |
Active-most recent confirmed post July 24, 2026 |
Technical Analysis :
- Operating model: Triple X operates a Tor-hosted data leak site ("Triple X WebBlog") and communicates and negotiates through an underground forum profile. Rather than following the classic encrypt-and-ransom model, the group emphasizes "free data" downloads accompanied by sample proof files, positioning it closer to a data-extortion operation than a confirmed file-encrypting ransomware family. No publicly available ransomware sample or encryption routine has been identified to date.
- Forum distribution activity: In addition to its dedicated leak site, Triple X (via actor handle "apt8172") actively cross-posts leak announcements to at least one underground cybercrime forum, under a "Bases and Leaks" category typically used to advertise stolen databases and credential dumps to a buyer audience, separate from ransomware-specific extortion boards. Key details observed from this forum profile:
- Account identifiers: Username "apt8172", forum ID 240235, registered May 13, 2026 the account was created within days of the group's first known activity, suggesting it was set up specifically to support this operation rather than being a long-standing established persona.
- Account status: "Paid registration" and "Autogarant" status both indicate the actor invested in a verified/vouched status on the forum, which underground marketplaces typically require to build buyer trust and reduce scam risk. This suggests premeditation and an intent toward repeat sales rather than a one-off post.
- Activity tags: The account is self-tagged "hacking," consistent with the group's positioning as a data-broker/hacking-focused seller rather than a classic ransomware crew.
- Posting behavior: The forum post advertising the Bank of Baroda data closely mirrors the leak-site post (same claimed data categories: personal banking, NetBanking, loans, NRI/corporate banking, customer support data) but adds a direct sample-download link and a separate full-data link, both hosted on the group's own onion infrastructure meaning the forum post functions as an advertisement funneling buyers back to Triple X's infrastructure rather than hosting stolen data on the forum itself.
- Assessment: This dual-channel approach (dedicated leak site + forum marketplace advertising) indicates Triple X is not solely running a shame-site extortion model but is actively marketing stolen data for direct sale to third-party buyers raising the risk profile beyond reputational damage to active resale and secondary exploitation of the stolen PII/financial data.
Victim:
|
Victim |
Sector |
Country |
Claimed Data |
Attack/Discovery Date |
|
Bank of Baroda (bankofbaroda.bank.in) |
Financial Services / Banking |
India |
~1 TB; 100,000–300,000 account-opening forms, national IDs, photos, NetBanking, loan, NRI & corporate banking data |
12 May 2026 (listed Jul 24, 2026) |
|
Bni.co.id (Bank Negara Indonesia) |
Financial Services / Banking |
Indonesia |
~2 TB; customer contracts, passports, ID cards (2024–2026) |
11 May 2026 |
|
immigrationonline.com (Law Offices US) |
Professional Services / Legal |
United States |
~1.5 TB; ~24,900 passport files, tax forms, SSNs, banking details, court case materials |
12 May 2026 |
Assessment: No initial-access vector, credential source, or exfiltration tooling has been confirmed for this actor. The group's narrative in its posts (e.g., attributing the Bank of Baroda incident to "weak password" practices) is unverified self-reporting by the threat actor and should not be treated as a confirmed root cause
Indicators of Compromise (IOCs)
|
Type |
Indicator |
Context |
|
Onion domain |
ojcmpbdncjo5dhaxxll44bq6to3kwqtoeraevgsjquhdtt4uv5l4igid[.]onion/ |
Primary leak site (DLS) |
|
Onion domain |
6qqz6m3b6htudohg2mlf5gdcalonxy3sh5g4dix4mpyirjcgelqqufad[.]onion |
Secondary download/data-hosting site |
MITRE ATT&CK
|
Tactic |
Technique ID |
Technique |
|
Resource Development |
T1583 |
Acquire Infrastructure |
|
Resource Development |
T1585 |
Establish Accounts |
|
Credential Access |
T1110 |
Brute Force |
|
Initial Access |
T1078 |
Valid Accounts |
|
Collection |
T1005 |
Data from Local System |
|
Exfiltration |
T1567 |
Exfiltration Over Web Service |
|
Impact |
T1654 |
Data Leak |
|
Impact |
T1657 |
Financial Theft |
Mitigation
- Credential hygiene: Enforce MFA on all customer-facing and administrative portals; rotate and audit credentials tied to account-opening/onboarding systems, a recurring exposure point across all three victims.
- PII/document handling: Encrypt at-rest storage for scanned ID documents, passports, and account-opening forms; apply strict access segmentation for high-volume PII repositories.
- Dark web monitoring: Continuously monitor Triple X's leak site and known forum identifiers for new claims referencing your organization or supply chain.
- Incident response readiness: Pre-stage IR engagement and legal counsel contacts; preserve forensic evidence before remediation if a listing appears.
- Third-party/vendor risk: Given targeting of a law firm handling client financial/PII data, extend monitoring to key vendors and professional services partners who hold sensitive client records.
Conclusion
Triple X is an active data-extortion group that emerged in May 2026 and has rapidly expanded its operations, targeting organizations in the financial services and legal sectors across India, Indonesia, and the United States. Its focus on large-scale theft of personally identifiable information (PII) and financial documents, rather than confirmed encryption-based attacks, indicates a data-monetization strategy centered on public data leaks and underground forum-based sales. Continued monitoring of the group's leak site and underground forum activity should remain a priority to identify new victim disclosures and emerging tactics.