Ransomware Group intelligence
Black X
ActiveTrack Black X with 15 published victims and 1 known leak locations in a single intelligence view.
Overview
Black X is tracked by Breach House as a ransomware group with 15 published victims.
Korea, Republic of is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Up checked 3h ago | blackxppq2jvqyg4slyg3sbszv7ib2avaaycvhff5qipgdoepqi57xyd.onion |
Top Activity Sectors (7)
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Black X, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: Black X executes malicious payloads via PowerShell to stage ransomware components and evade static detection.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: Black X disables security tools by terminating antivirus processes and modifying system behaviors to prevent recovery.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: Black X deletes Volume Shadow Copies and backup artifacts via system commands to eliminate recovery options.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1564.003 Hidden Window Stealth
What they do: Black X hides malicious activity through hidden windows and stealthy process execution to avoid endpoint detection.
What that means: Adversaries may use hidden windows to conceal malicious activity from the plain sight of users.
-
T1083 File and Directory Discovery Discovery
What they do: Black X performs file and directory discovery to identify critical documents, backups, and system paths for encryption.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1135 Network Share Discovery Discovery
What they do: Black X uses network share discovery to locate victim file shares and target high-value data across networked environments.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1560.001 Archive via Utility Collection
What they do: Black X archives stolen data using utility commands before exfiltration to support ransom demands.
What that means: Adversaries may use utilities to compress and/or encrypt collected data prior to exfiltration.
-
T1486 Data Encrypted for Impact Impact
What they do: Black X encrypts victim files using custom ransomware routines to maximize operational disruption and extortion leverage.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1489 Service Stop Impact
What they do: Black X stops critical services such as backup and monitoring processes to disrupt victim incident response.
What that means: Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
-
T1490 Inhibit System Recovery Impact
What they do: Black X inhibits system recovery by corrupting restore points and disabling backup services before impact.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Victims (15)
Search, filter and paginate the victim timeline for Black X. Showing 1–15 of 15.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | FE CREDIT id32306 View details | Viet Nam | Finance / Legal / Insurance | ||
|
www.fecredit.com.vn operates within the finance, legal, and insurance sectors and is situated in Vietnam. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim, with the associated threat actor or source designated as Black X. The description focuses on the entity's identity, geographic context, industry classification, and its documented placement within the ransomware victim classification linked to Black X. No specific incident details such as stolen data, record counts, ransom amounts, or confirmed breach specifics are included, adhering to factual neutrality and analytical restraint. |
|||||
| Ransomware | FE CREDIT id32306 View details | Viet Nam | Finance / Legal / Insurance | ||
|
We have obtained the personal information of your company's millions of customers. If the reverse clock is terminated, customer information will be leaked from our site. Please contact us to prevent customer information leakage. |
|||||
| Ransomware | i-one id32307 View details | Korea, Republic of | IT | ||
|
www.i-one.co.kr is an entity operating within the IT sector located in Korea. Its domain name and operational profile align with a technology-focused organization serving regional digital services. It has been cataloged in this threat-intelligence index under the listing type ransomware victim, specifically associated with the threat actor Black X. This designation reflects its inclusion within cybersecurity records documenting ransomware-related incidents affecting entities in the IT domain. The entry provides neutral context for analysts tracking threat actor activity and victim profiles across sectors and geographies. |
|||||
| Ransomware | i-one id32307 View details | Korea, Republic of | IT | ||
|
This company is a manufacturer of car parts. We have obtained all of your company's technical data. (1TByte) If you do not contact us, all your data, including technical, sales, drawings, quality, logistics, and supply chain information, will be leaked. |
|||||
| Ransomware | sanaa hospital id31029 View details | Yemen | Healthcare / Pharma | ||
|
Sanaa Hospital is a healthcare facility located in Yemen, providing medical services to patients in the region. As a hospital, it offers various healthcare services, including emergency care, surgical procedures, and outpatient treatments. Sanaa Hospital was listed as a ransomware victim associated with Black X. |
|||||
| Ransomware | sanaa hospital id31029 View details | Yemen | Healthcare / Pharma | ||
|
[AI generated] N/A |
|||||
| Ransomware | Tong Kong E & E Sdn Bhd (95907X) id31030 View details | Malaysia | Other | ||
|
Tongkong is a Malaysian entity operating in the other sector. The entity is accessible through the https://wa.me/tongkong link. It was listed as a ransomware victim associated with Black X. |
|||||
| Ransomware | Tong Kong E & E Sdn Bhd (95907X) id31030 View details | Malaysia | Other | ||
|
It contains sensitive data, including customers and banking records. |
|||||
| Ransomware | sanaa id30613 View details | Yemen | Education | ||
|
The Sanaa Center is an educational institution based in Yemen, providing educational services to the local community. As an organization in the education sector, it plays a vital role in the country's development. Sanaa Center was listed as a ransomware victim associated with Black X. |
|||||
| Ransomware | sanaa id30613 View details | Yemen | Education | ||
|
[AI generated] N/A |
|||||
| Ransomware | Daechang Solution id29850 View details | Korea, Republic of | IT | ||
|
We possess all the core technical data of Daechang Solution. (Technical Research Institute, Valve Team, Cryogenic Team, Innovation Team, Sales Team, Finance Team, Materials Team, Quality Team, General Affairs Team, Production Team) we will sell it to only one. |
|||||
| Ransomware | elektroverband-bayern id29558 View details | Germany | NGOs / Associations | ||
|
The State Guild Association for the Bavarian Electrical Trades is the umbrella organization of 25 Bavarian electrical guilds. It represents the interests of approximately 3,000 craft businesses from the following electrical trades: Electrical engineering trade Information technology trade Electrical machine manufacturing trade The State Guild Association offers its members comprehensive information services in the fields of business administration, technology, law, and management. It focuses on initial and continuing training, promotes the exchange of experience through regular specialist conferences and workshops as well as participation in trade fairs, conducts consistent public relations work, is responsible for negotiating collective bargaining agreements, and supports its member companies in implementing family-friendly personnel policies. Furthermore, the State Guild Association advocates for the interests of its members at the state and federal levels in a variety of ways and develops concepts for joint market activities together with industry, wholesalers, and electricity suppliers. The guiding principles of the Bavarian State Guild Association The member companies of the Bavarian State Guild Association for the Electrical Trades have adopted the following mission statement. The mission statement of the Bavarian electrical trades serves as Guidance and decision-making support for each individual member company Guidelines for the guilds and the state guild association in representing the interests of member companies Policy paper for the dissemination of information to the public The Bavarian electrical trade, with approximately 3,000 companies, around 87,300 employees, and roughly €15 billion in revenue, provides comprehensive information, planning, manufacturing, sales, installation, and maintenance of electrotechnical and electronic devices, systems, and equipment throughout the region. The three electrical trades (electrical engineer, information technology specialist, and electrical machine builder) are practiced extensively and complementarily. They are organized into electrical guilds. |
|||||
| Ransomware | African National Congress id29559 View details | South Africa | NGOs / Associations | ||
|
The ANC is a national liberation movement. It was formed in 1912 to unite the African people and spearhead the struggle for fundamental political, social and economic change. For ten decades the ANC has led the struggle against racism and oppression, organising mass resistance, mobilising the international community and taking up the armed struggle against apartheid. The ANC achieved a decisive democratic breakthrough in the 1994 elections, where it was given a firm mandate to negotiate a new democratic Constitution for South Africa. The new Constitution was adopted in 1996. The ANC was re-elected in 1999 to national and provincial government with an increased mandate. The policies of the ANC are determined by its membership and its leadership is accountable to the membership. Membership of the ANC is open to all South Africans above the age of 18 years, irrespective of race, colour and creed, who accept its principles, policies and programmes. |
|||||
| Ransomware | case.law id29560 View details | Philippines | NGOs / Associations | ||
|
Since incorporation in 1972, CRS has delivered services to a diverse group of clients, primarily in the corrections and detention fields, at the local, regional, state, and national levels. We stole passport data from over 300 customers at CRS. |
|||||
| Ransomware | Wonjin Plastic Surgery id29561 View details | Korea, Republic of | Manufacturing / Engineering | ||
|
WJ Wonjin's medical staff work to achieve the optimal effect according to each individual patient's condition and desired result. Our medical services are provided by specialist doctors on-site, and our interpreting coordinators assist throughout the whole process. Safest Anesthesia System by Exclusive Anesthesiologists. We value our patients' safety during their surgery using cutting edge anesthesia system. Fully equipped with specialized medical facilities and system from the very beginning, we value safety for our patients. |
|||||