Ransomware group profile · #688 by claimed victims
Xp95 ransomware
XP95 is a cyber-extortion group that emerged in March 2026, using a pure data-theft-and-extortion model with a Windows XP/95-themed leak site, with notable targets including Statistics South Africa (154 GB exfiltrated) and the Gauteng Provincial Government.
Tactics, techniques and procedures
ATT&CK technique mapping for Xp95 is in progress. Victimology, infrastructure status and leak-site tracking are live above.
Indicators, detections and the full playbook
Hashes, C2 addresses, onion services, Sigma and YARA detections per technique, and the negotiation transcripts are available to signed-in analysts.
Frequently asked
Is Xp95 ransomware still active?
How many victims has Xp95 claimed?
Which industries does Xp95 target?
Which countries are most affected by Xp95?
Where does VULONE get Xp95 victim data?
Other ransomware groups
Victim claims are collected from leak sites and enrichment partners (ransomware.live, RansomLook) and represent the group's own assertions, not confirmed breaches. Profile last updated 16 September 2026. Questions or corrections: [email protected].