Ransomware Group intelligence
Teamxxx
InactiveTrack Teamxxx with 19 published victims and 1 known leak locations in a single intelligence view.
Overview
Teamxxx is tracked by Breach House as a ransomware group with 19 published victims.
United States is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Down checked 59m ago | tp5cwh6d2b5hekcg6jlhoe6mawa7dlwiv47epvnfmzuaaur2dnaa3uid.onion |
Top Activity Sectors (7)
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Teamxxx, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: teamxxx uses PowerShell scripts to execute malicious commands and deploy payloads across victim systems.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: teamxxx modifies Windows Registry Run Keys to ensure malware execution upon system reboot for persistence.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: teamxxx disables antivirus tools and security software to evade detection during initial compromise.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: teamxxx deletes Volume Shadow Copies and backup directories to prevent data recovery and increase victim pressure.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1018 Remote System Discovery Discovery
What they do: teamxxx performs remote system discovery to identify additional hosts within the victim network for spreading.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1049 System Network Connections Discovery Discovery
What they do: teamxxx queries system network connections to identify active services and potential exfiltration paths.
What that means: Adversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network.
-
T1135 Network Share Discovery Discovery
What they do: teamxxx scans network shares to discover accessible directories for lateral movement and victim targeting.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: teamxxx exploits SMB/Windows Admin Shares to move laterally between compromised hosts in the network.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: teamxxx encrypts victim files using a custom ransomware payload to maximize impact and extortion leverage.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: teamxxx invokes system recovery inhibitors to prevent IT teams from restoring systems independently.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Victims (19)
Search, filter and paginate the victim timeline for Teamxxx. Showing 1–19 of 19.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Scania.com id21526 View details | Sweden | Manufacturing / Engineering | ||
|
[AI generated] Scania is a leading Swedish company that specializes in the production of heavy trucks, buses, and other commercial vehicles. It is also known for manufacturing diesel engines for heavy vehicles and marine and industrial applications. Founded in 1891, Scania has numerous subsidiaries and operates in over 100 countries, providing innovative transportation solutions focused on sustainability and efficiency. |
|||||
| Ransomware | Intercommunityct.org id21118 View details | United States | Communication / Marketing | ||
|
[AI generated] Intercommunityct.org is associated with InterCommunity Inc., a community-based health organization in Connecticut that caters to the needs of local residents. The organization provides a range of comprehensive, high-quality, and easily accessible health services including mental health and addiction services, primary care, recovery and wellness programs. They focus on supporting individuals and families in the community to achieve their fullest potential through these services. |
|||||
| Ransomware | Websterhenry.com id21099 View details | United States | Other | ||
|
[AI generated] N/A |
|||||
| Ransomware | Nationwidecare.org id20818 View details | United Kingdom | Other | ||
|
[AI generated] "N/A" |
|||||
| Ransomware | etoscapitalasia.com id20769 View details | Hong Kong | Other | ||
|
etoscapitalasia.com is a Hong Kong-based entity in the Other sector, with no reliable public source in the provided search results describing its specific offerings or business model. Hong Kong is widely recognized as an international business and financial center, but the available results do not confirm the company’s exact line of activity. For cataloging purposes, the entity should be treated neutrally and identified only by the domain, sector, and jurisdiction supplied. It was listed as a ransomware victim associated with teamxxx. |
|||||
| Ransomware | aetoscapitalasia.com id20817 View details | Hong Kong | Other | ||
|
[AI generated] N/A |
|||||
| Ransomware | eterpauper id20565 View details | United States | Other | ||
|
eterpauper is a US-based entity categorized in the Other sector, indicating a business or organization outside a more specific industry label. Public listings describe it as operating in the United States and do not provide additional verified details about its products or services in the available source. In threat-intelligence catalogs, such entries are used to index organizations that appear on ransomware victim lists for situational awareness. eterpauper was listed as a ransomware victim associated with teamxxx. |
|||||
| Ransomware | peterpauper id20816 View details | United States | Other | ||
|
[AI generated] N/A |
|||||
| Ransomware | nteriorsgroup.ie id20564 View details | Ireland | Services | ||
|
The Interiors Group is a professional fit out services company based in Ireland, operating within the Services sector with over 20 years of experience delivering high-quality environments for diverse clients. The company specializes in providing premium fit out solutions, leveraging extensive expertise to create stunning and functional spaces for a wide range of customers. As a trusted provider in the Irish market, The Interiors Group is recognized for its commitment to quality and client satisfaction in the fit out industry. The company was listed as a ransomware victim associated with the threat actor teamxxx. |
|||||
| Ransomware | interiorsgroup.ie id20815 View details | Ireland | Services | ||
|
[AI generated] N/A |
|||||
| Ransomware | arvikhavn.no id20563 View details | Norway | Transportation / Travel / Logistics | ||
|
arvikhavn.no appears to be a Norway-based transportation and travel entity associated with maritime and port-related operations, reflecting a sector tied to travel, logistics, and public-facing movement services. Publicly available references suggest the name aligns with the Norwegian port and urban-development context around Havn/By & Havn-style operations, but the domain itself does not provide enough visible detail here to confirm a more specific service profile. In threat-intelligence listings, it is categorized as a ransomware victim linked to the actor teamxxx. The listing does not by itself establish the scope, impact, or full circumstances of any incident. |
|||||
| Ransomware | narvikhavn.no id20814 View details | Norway | Transportation / Travel / Logistics | ||
|
[AI generated] "ArvikHavn.no" is a Norwegian information service that focuses on the area around the Arvik Harbor. It provides news, reports, and valuable guidelines related to the harbor activities. The site caters to the interests of residents, businesses, tourists, and general visitors who need information about the area, including tourism, local events, fishing activities, and harbor regulations. |
|||||
| Ransomware | vent-medical.com id20562 View details | Czechia | Healthcare / Pharma | ||
|
vent-medical.com operates as a Healthcare and Pharma sector entity focused on respiratory care solutions, specifically designing and manufacturing advanced mechanical ventilators for critical care. The company, associated with the Czech region, dedicates its mission to enabling clinicians to provide world-class ventilation while reducing costs through high-performance, cost-effective mechanical ventilator technology. Its offerings include patented Swiss pneumatic technology ventilators such as Inspiration® and eVolution® for critical care applications. vent-medical.com was listed as a ransomware victim associated with the threat actor teamxxx. |
|||||
| Ransomware | event-medical.com id20813 View details | Czechia | Healthcare / Pharma | ||
|
[AI generated] Vent-Medical is a healthcare company specializing in respiratory care and artificial ventilation. They offer medical devices like nasal pillows, full-face masks and other respiratory equipment mainly for healthcare professionals and hospitals. Their mission is to improve patient care by offering high-quality ventilation solutions. |
|||||
| Ransomware | ationwidecare.org id20561 View details | United Kingdom | Other | ||
|
[AI generated] N/A |
|||||
| Ransomware | ebberrestaurantgroup.com id20560 View details | Hospitality / Food & Beverage / Tourism | |||
|
ebberrestaurantgroup.com is associated with a U.S.-based hospitality business in the food and beverage sector, a category that serves restaurants and related guest-facing services. The hospitality industry also spans tourism and travel-related offerings that support customer experiences across dining, recreation, and destination services. Publicly available references to the domain indicate a restaurant-group identity, but detailed company background and location-specific operations are not clearly disclosed in the available sources. It was listed as a ransomware victim associated with teamxxx. |
|||||
| Ransomware | webberrestaurantgroup.com id20812 View details | Hospitality / Food & Beverage / Tourism | |||
|
[AI generated] N/A |
|||||
| Ransomware | elkorpAg.com id20559 View details | Germany | Other | ||
|
elkorpAg.com appears to be a Germany-based organization in the broad Other sector, with public references indicating a corporate or brand-facing web presence under that domain. The available evidence does not clearly identify its specific products or services, so the listing should be treated as a neutral index entry rather than a detailed company profile. In threat-intelligence catalogs, such entries are used to organize victim-related disclosures by entity, sector, and country for easier analysis. It was listed as a ransomware victim associated with teamxxx. |
|||||
| Ransomware | BelkorpAg.com id20811 View details | Germany | Other | ||
|
[AI generated] N/A |
|||||