M3rx

Active
M3rx is a small ransomware group first observed in 2025, using AES-CTR/AES-GCM encryption and targeting organizations in England, the US, Australia, Germany, Italy, and Switzerland, with around eight claimed victims including a Sydney-based property firm.
37 Victims
Apr 29, 2026 First Discovered
Aug 14, 2026 Last Discovered
33 Days Inactive
0% Infostealer
1/2 Sites Online
Known Locations (2)
M3RX Data Leak Site
4k6plf4h2cm2nco6ae3inrsxnmqgl6lllmwefydhnlcq4tuhwbj4qpad.onion
pippahtohg6qgioqu3ixrsueefuw7thythmmeanyrgwn3eixcuu6jvqd.onion
Intelligence
Victims (37)

Detailed victim list temporarily unavailable

This group has 37 victims. The victim list API is currently responding slowly for this dataset. Country, sector, and infostealer breakdowns are not available at this time. Basic stats (victim count, first/last seen) are shown above from a faster data source.