Ransomware group profile · #683 by claimed victims
X001Xs ransomware
X001xs is a low-profile ransomware group tracked on monitoring platforms with minimal public documentation, employing standard double-extortion tactics with no detailed technical analysis published by major vendors.
Tactics, techniques and procedures
ATT&CK technique mapping for X001Xs is in progress. Victimology, infrastructure status and leak-site tracking are live above.
Indicators, detections and the full playbook
Hashes, C2 addresses, onion services, Sigma and YARA detections per technique, and the negotiation transcripts are available to signed-in analysts.
Frequently asked
Is X001Xs ransomware still active?
How many victims has X001Xs claimed?
Which industries does X001Xs target?
Which countries are most affected by X001Xs?
Where does VULONE get X001Xs victim data?
Other ransomware groups
Victim claims are collected from leak sites and enrichment partners (ransomware.live, RansomLook) and represent the group's own assertions, not confirmed breaches. Profile last updated 16 September 2026. Questions or corrections: [email protected].