Uptime Hamster: 22d 4h 37mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza blogxx

blogxx

0 incidentes 0 paises 0 sectores ransomware RU Ultimo: -
Ver en IntelTracker → APTTrail →
BlogXX is a financially motivated ransomware group that emerged in April 2022, operating under a Ransomware-as-a-Service model. The group is widely believed to be a relaunch or direct variant of the defunct REvil ransomware operation, leveraging similar code and employing the alias Sodinokibi in private negotiations. Its primary motivation is financial gain through double extortion, which involves encrypting victim data while also stealing sensitive information for public release if a ransom is not paid. A distinguishing characteristic of BlogXX is its strong, almost synonymous, link to the previous REvil infrastructure and methodology, making it difficult to differentiate where one ends and the other begins, which suggests a continuation of operations under a new guise following law enforcement disruptions against REvil.
Tipo
ransomware
Pais origen
RU
Motivacion
-
Impacto
28
Actualizado
Fri, 19 Ju

Paises objetivo (SOCRadar)

AustraliaBrazilCanadaGermanyUnited KingdomIndiaKorea, Republic ofMexicoSwedenTaiwan, Province of China

Sectores objetivo (SOCRadar)

Energy & Utilities ManufacturingWholesale TradeRetailTransportation&WarehousingFinanceProfessional&Technical ServicesEducational ServicesHealthCare & Social AssistancePublic Administration