Ransomware Group intelligence
Triple X
ActiveTrack Triple X with 6 published victims and 2 known leak locations in a single intelligence view.
Overview
Triple X is tracked by Breach House as a ransomware group with 6 published victims.
India is currently the most targeted country in this dataset.
2 known leak locations are currently associated with this group.
Leak Status Distribution
No leak-status data available yet.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (2)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 2 | Onion service | Down checked 4h ago | ojcmpbdncjo5dhaxxll44bq6to3kwqtoeraevgsjquhdtt4uv5l4igid.onion |
| Leak location 1 | Onion service | Down checked 4h ago | 6qqz6m3b6htudohg2mlf5gdcalonxy3sh5g4dix4mpyirjcgelqqufad.onion |
Top Activity Sectors (2)
Typical Attacks (8)
▼MITRE ATT&CK does not currently catalogue Triple X, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: Triple X executes malicious payloads via PowerShell scripts to perform discovery, privilege escalation, and lateral movement.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1569.002 Service Execution Execution
What they do: Triple X executes ransomware binaries through Windows Service activation to ensure persistence and broad system coverage.
What that means: Adversaries may abuse the Windows service control manager to execute malicious commands or payloads.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: Triple X disables security tools by terminating antivirus processes and modifying Windows Defender settings to evade detection.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: Triple X deletes Volume Shadow Copies and backup directories via vssadmin and built-in file deletion commands to prevent recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1135 Network Share Discovery Discovery
What they do: Triple X uses network share discovery to locate victim file shares and identify high-value data for exfiltration or encryption.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1041 Exfiltration Over C2 Channel Exfiltration
What they do: Triple X exfiltrates stolen data over encrypted C2 channels before deploying ransomware to maximize extortion leverage.
What that means: Adversaries may steal data by exfiltrating it over an existing command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: Triple X encrypts victim files using custom ransomware binaries targeting finance, legal, and insurance documents.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: Triple X inhibits system recovery by corrupting restore points and disabling backup restoration mechanisms post-encryption.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Victims (6)
Search, filter and paginate the victim timeline for Triple X. Showing 1–6 of 6.
| Type | Target | Discovered | Country | Business Category | Intel Link | Leak status |
|---|---|---|---|---|---|---|
| Ransomware | Henshaw Law id31287 View details | United Kingdom | Finance / Legal / Insurance | — | — | |
|
Henshaw Law is a legal services firm based in the United Kingdom, operating within the finance and insurance sector. The company provides legal advice and services to clients. Henshaw Law was listed as a ransomware victim associated with Triple X |
||||||
| Ransomware | Henshaw Law id31287 View details | United Kingdom | Finance / Legal / Insurance | — | — | |
|
1 terabytes of people's data https://henshawlawak.com/ Henshaw Law, Despite repeated recommendations, no action was taken. The problem remains unresolved, the system is full of bugs, people's documents are at risk, and they won't take any responsibility. Multiple people could commit suicide, what important information has been leaked about them, and who is responsible for why the recommendations weren't taken seriously. what data will leak ? -Personal family files -Passports and licenses -Court ruling and public complaint forms -Documents scans -Forms and emails scans sample : Full download data link : Download |
||||||
| Ransomware | Bank of Baroda bigest indian bank bankofbaroda.bank.in id30829 View details | India | Finance / Legal / Insurance | — | — | |
|
Bank of Baroda is a prominent Indian bank operating in the finance sector, offering various banking and financial services to its customers in India. As a major financial institution, it plays a significant role in the country's economy. Bank of Baroda was listed as a ransomware victim associated with Triple X. |
||||||
| Ransomware | Bank of Baroda bigest indian bank bankofbaroda.bank.in id30829 View details | India | Finance / Legal / Insurance | — | — | |
|
1 terabytes of people's data https://bankofbaroda.bank.in/ Imagine I'm going to the bank to open an account. and due to the bank's weak password and mistake, my personal data should be leaked, and fraudsters should use my resources in scam people and verify exchangers shops and fraudulent schemes. How many years should I be held responsible to the police and for complaints? its fair ? Yes, approximately 100 to 300 thousand forms from people who had given their personal information/documents to the bank for opening accounts filled out forms and even photographs with their national ID cards all of it is downloadable for free. what data will leak ? -Personal Banking (Savings accounts, current accounts, etc.) -NetBanking (bob World Internet for corporate and retail users) -Loans (Personal, Home, Car, and Education loans) -NRI & Corporate Banking Services -Customer support and branch/ATM locator services. Sapmle data (check what you will download) : Download few sample pics: pic 1 pic 2 pic 3 pic 4 pic 5 pic 6 pic 7 ) Full download data link : Download |
||||||
| Ransomware | Bni.co.id bank of indonesia free data. id29851 View details | Indonesia | Finance / Legal / Insurance | — | ||
|
BANK of indonesia bni.co.id Customer information from 2024 to 2026 All customer contracts, passports, and ID cards (few pic attached) It’s strange the bank has such a severe security weakness. full data is 2 TB few sample pics: pic 1 pic 2 pic 3 pic 4 pic 5 part 1 ~ 100Gig free download : http://6qqz6m3b6htudohg2mlf5gdcalonxy3sh5g4dix4mpyirjcgelqqufad.onion/bni.co.id/ pass : bnibnibni we will leak few days later new parts, if u wanna download full pack PM us in forums (https://forum.exploit.in/profile/240235-apt8172/) and get link. If you want to buy the bni bank 2026 fresh data, send a private message... |
||||||
| Ransomware | Law Offices US immigrationonline.com id29852 View details | United States | Services | — | ||
|
https://immigrationonline.com/ 1.5 terabytes of people's data in a immigrationonline law firm. Server overload and lack of updates have caused important data to be exposed to potential leaks. At the same time, many of these financial and tax documents also contain sensitive personal information, including full names, home addresses, Social Security numbers, banking details, and contact information. what will leak ? Confidential court cases : Details of lawsuits, complaints, or defenses that have not yet been filed in court. Financial and banking information : Sensitive client accounts, contracts, or transactions. Intellectual property documents : Such as patents, designs, or business contracts that have not yet been made public. Private correspondence and emails : Communications between the attorney and the client that should remain strictly confidential. what data will leak ? 24,900 passport files sample Tax forms of employees and colleagues sample ID cards and driver’s licenses sample few sample pics: pic 1 pic 2 pic 3 pic 4 pic 5 This is probably the right moment to point out that, at a certain stage, virtually any data breach is still a reversible situation. Companies are usually given an opportunity to contain the damage and resolve the issue albeit at a price. But despite knowing exactly what was happening, and fully understanding that it was putting the security and privacy of its own employees at risk, the company made a calculated decision to let it happen. And now the company will tell its employees: “Sorry, we’ve experienced a data breach, and your passports are now publicly available online.” But they will never say: “We were offered a chance to pay to prevent your passports from being published, but we decided it wasn’t worth it so now they’re on the internet. Sorry.” download data link : http://6qqz6m3b6htudohg2mlf5gdcalonxy3sh5g4dix4mpyirjcgelqqufad.onion/immigrationonline.com/ |
||||||