CRITICALFortiBleed is actively compromising Fortinet firewalls. Is your domain exposed?
Run free scan
CyberXtron
Inside Triple X: A New Ransomware Group Targeting Banks and Law Firms
#cyberxtron#Triple X#Ransomware#Bank#ThreatIntel

Inside Triple X: A New Ransomware Group Targeting Banks and Law Firms

Executive Summary :

Triple X is a financially motivated data-extortion group first observed in May 2026, with three claimed victims (India, Indonesia, US) across financial services and legal sectors, totaling over 4.5 TB of claimed data. The most severe incident, disclosed July 24, 2026, targeted Bank of Baroda, with claims of 100,000–300,000 leaked account-opening forms containing national IDs, photos, and financial data. The group runs a dark-web leak site and free-data extortion model, publicly posting samples to pressure victims. No publicly available evidence currently confirms the malware, initial access vector, or encryption methodology used by the group. Its TTP profile remains provisional. 

Threat Actor Overview :

Field 

Details 

Threat Name 

Triple X (also referenced as "TripleX") 

Threat Type 

Data Extortion / Ransomware Group (data broker–style operation; leak site–based free-data extortion) 

Motivation 

Financial gain-monetizes stolen data via public leak-site posts, direct sale/PM negotiation on forums, and reputational pressure on victims 

First Observed 

Mid-to-late May 2026 

Status 

Active-most recent confirmed post July 24, 2026 

Technical Analysis :

  • Operating model:  Triple X operates a Tor-hosted data leak site ("Triple X WebBlog") and communicates and negotiates through an underground forum profile. Rather than following the classic encrypt-and-ransom model, the group emphasizes "free data" downloads accompanied by sample proof files, positioning it closer to a data-extortion operation than a confirmed file-encrypting ransomware family. No publicly available ransomware sample or encryption routine has been identified to date. 
  •  Forum distribution activity: In addition to its dedicated leak site, Triple X (via actor handle "apt8172") actively cross-posts leak announcements to at least one underground cybercrime forum, under a "Bases and Leaks" category typically used to advertise stolen databases and credential dumps to a buyer audience, separate from ransomware-specific extortion boards. Key details observed from this forum profile: 
  • Account identifiers: Username "apt8172", forum ID 240235, registered May 13, 2026  the account was created within days of the group's first known activity, suggesting it was set up specifically to support this operation rather than being a long-standing established persona. 
  • Account status: "Paid registration" and "Autogarant" status both indicate the actor invested in a verified/vouched status on the forum, which underground marketplaces typically require to build buyer trust and reduce scam risk. This suggests premeditation and an intent toward repeat sales rather than a one-off post. 
  • Activity tags: The account is self-tagged "hacking," consistent with the group's positioning as a data-broker/hacking-focused seller rather than a classic ransomware crew. 
  • Posting behavior: The forum post advertising the Bank of Baroda data closely mirrors the leak-site post (same claimed data categories: personal banking, NetBanking, loans, NRI/corporate banking, customer support data) but adds a direct sample-download link and a separate full-data link, both hosted on the group's own onion infrastructure  meaning the forum post functions as an advertisement funneling buyers back to Triple X's infrastructure rather than hosting stolen data on the forum itself. 
  • Assessment: This dual-channel approach (dedicated leak site + forum marketplace advertising) indicates Triple X is not solely running a shame-site extortion model but is actively marketing stolen data for direct sale to third-party buyers  raising the risk profile beyond reputational damage to active resale and secondary exploitation of the stolen PII/financial data. 

Victim: 

Victim 

Sector 

Country 

Claimed Data 

Attack/Discovery Date 

Bank of Baroda (bankofbaroda.bank.in) 

Financial Services / Banking 

India 

~1 TB; 100,000–300,000 account-opening forms, national IDs, photos, NetBanking, loan, NRI & corporate banking data 

12 May 2026 (listed Jul 24, 2026) 

Bni.co.id (Bank Negara Indonesia) 

Financial Services / Banking 

Indonesia 

~2 TB; customer contracts, passports, ID cards (2024–2026) 

11 May 2026 

immigrationonline.com (Law Offices US) 

Professional Services / Legal 

United States 

~1.5 TB; ~24,900 passport files, tax forms, SSNs, banking details, court case materials 

12 May 2026 

Assessment: No initial-access vector, credential source, or exfiltration tooling has been confirmed for this actor. The group's narrative in its posts (e.g., attributing the Bank of Baroda incident to "weak password" practices) is unverified self-reporting by the threat actor and should not be treated as a confirmed root cause 

Indicators of Compromise (IOCs) 

Type 

Indicator 

Context 

Onion domain 

ojcmpbdncjo5dhaxxll44bq6to3kwqtoeraevgsjquhdtt4uv5l4igid[.]onion/ 

Primary leak site (DLS) 

Onion domain 

6qqz6m3b6htudohg2mlf5gdcalonxy3sh5g4dix4mpyirjcgelqqufad[.]onion 

Secondary download/data-hosting site 

MITRE ATT&CK 

Tactic 

Technique ID 

Technique 

Resource Development 

T1583 

Acquire Infrastructure 

Resource Development 

T1585 

Establish Accounts 

Credential Access 

T1110 

Brute Force  

Initial Access 

T1078 

Valid Accounts  

Collection 

T1005 

Data from Local System  

Exfiltration 

T1567 

Exfiltration Over Web Service 

Impact 

T1654 

Data Leak 

Impact 

T1657 

Financial Theft 

 

Mitigation 

  • Credential hygiene: Enforce MFA on all customer-facing and administrative portals; rotate and audit credentials tied to account-opening/onboarding systems, a recurring exposure point across all three victims. 
  • PII/document handling: Encrypt at-rest storage for scanned ID documents, passports, and account-opening forms; apply strict access segmentation for high-volume PII repositories. 
  • Dark web monitoring: Continuously monitor Triple X's leak site and known forum identifiers for new claims referencing your organization or supply chain. 
  • Incident response readiness: Pre-stage IR engagement and legal counsel contacts; preserve forensic evidence before remediation if a listing appears. 
  • Third-party/vendor risk: Given targeting of a law firm handling client financial/PII data, extend monitoring to key vendors and professional services partners who hold sensitive client records. 

 Conclusion 

Triple X is an active data-extortion group that emerged in May 2026 and has rapidly expanded its operations, targeting organizations in the financial services and legal sectors across India, Indonesia, and the United States. Its focus on large-scale theft of personally identifiable information (PII) and financial documents, rather than confirmed encryption-based attacks, indicates a data-monetization strategy centered on public data leaks and underground forum-based sales. Continued monitoring of the group's leak site and underground forum activity should remain a priority to identify new victim disclosures and emerging tactics. 

 

 

 

Elevate your security—get curated threat insights in your inbox.

Inside Triple X: A New Ransomware Group Targeting Banks and Law Firms | CyberXTron Blog