Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Teamxxx

TeamXXX is an emerging ransomware group that launched its leak site in June 2025, claiming victims across healthcare, agriculture, hospitality, financial services, and shipping sectors in the US, UK, Norway, Ireland, and Europe within its first months.

Victims
12
 
First Discovered
2025-06-10
victim
Last Discovered
2025-08-04
victim
Inactive Since
287
days
Avg Delay
44.6
days
Infostealer
8.3%
victims with domain
Countries
8
hit
View Victims on World Map View Group Statistics
Attack Velocity — Last 12 months

Known Locations (1)
Favicon Title Type Available Last Visit Server Info FQDN
favicon No 2026-04-28T07:21:58 tp5cwh6d2b5hekcg6jlhoe6mawa7dlwiv47epvnfmzuaaur2dnaa3uid.onion

Target
Top 5 Activity Sectors
  • Healthcare 4
  • Transportation/Logistics 2
  • Business Services 1
  • Financial Services 1
  • Hospitality and Tourism 1
Top 5 Countries
  • US flag United States 3
  • GB flag United Kingdom 2
  • SE flag Sweden 1
  • HK flag Hong Kong 1
  • IE flag Ireland 1

Heatmap

YARA Rules (1)

Indicators of Compromise (IoCs) (1)
IP Address 1
Type IOC
IP Address 82.147.84.232

Victims (12)
Logo
Discovered: 2025-08-04 (9mo ago)  ·  Attack est.: 2025-08-03
[AI generated] Scania is a leading Swedish company that specializes in the production of heavy truck…
Logo
Discovered: 2025-07-12 (10mo ago)  ·  Attack est.: 2025-07-03
[AI generated] Intercommunityct.org is associated with InterCommunity Inc., a community-based health…
Logo
Discovered: 2025-07-11 (10mo ago)  ·  Attack est.: 2025-07-02
[AI generated] N/A…
Logo
Discovered: 2025-06-25 (10mo ago)  ·  Attack est.: 2025-04-28
[AI generated] "N/A"…
Logo
Discovered: 2025-06-22 (10mo ago)  ·  Attack est.: 2025-06-20
[AI generated] N/A…
Logo
Discovered: 2025-06-10 (11mo ago)  ·  Attack est.: 2025-02-17
[AI generated] N/A…
Logo
Discovered: 2025-06-10 (11mo ago)  ·  Attack est.: 2025-03-01
[AI generated] N/A…
Logo
Discovered: 2025-06-10 (11mo ago)  ·  Attack est.: 2025-03-03
[AI generated] "ArvikHavn.no" is a Norwegian information service that focuses on the area around the…
Logo
Discovered: 2025-06-10 (11mo ago)  ·  Attack est.: 2025-04-22
[AI generated] Vent-Medical is a healthcare company specializing in respiratory care and artificial …
Logo
Discovered: 2025-06-10 (11mo ago)  ·  Attack est.: 2025-04-28
[AI generated] N/A…
Logo
Discovered: 2025-06-10 (11mo ago)  ·  Attack est.: 2025-06-01
[AI generated] N/A…
Logo
Discovered: 2025-06-10 (11mo ago)  ·  Attack est.: 2025-04-29
[AI generated] N/A…