M3RX
M3rx is a ransomware and data-extortion operation that emerged publicly in 2026.
Profile source: Mallory opens in a new tabM3RX
Family profile
M3rx is a ransomware and data-extortion operation that emerged publicly in 2026. It is also referenced as M3RX and M3RXDLS, which appear to denote the same activity. The group operates a leak site and victim negotiation infrastructure and has been linked to a Windows x64 encryptor written in Go. Publicly observed victim postings indicate active operations rather than a purely notional brand.
Observed targeting spans multiple countries, including the United States, Canada, Mexico, the United Kingdom, Germany, Norway, Ireland, South Africa, Taiwan, Argentina, Australia, and Switzerland. Victims have included organizations in logistics and transportation, business and professional services, manufacturing, hospitality, consulting, legal services, property consultancy, and at least one managed security service provider. This pattern suggests broad opportunistic targeting rather than a narrowly specialized vertical focus.
M3rx conducts double-extortion style ransomware operations, combining file encryption with claims of data theft and leak-site publication pressure. Reported victim entries frequently include alleged exfiltration volumes and file counts, indicating that public shaming and disclosure threats are central to its coercion model. The ransom process includes direct operator contact and negotiation, with offers to decrypt a limited number of files as proof of capability.
The malware associated with M3rx uses modern cryptographic design. Analysis of a linked sample found per-run X25519 key exchange, AES-CTR for file content encryption, and AES-GCM to protect per-file encryption keys, with encrypted files receiving a fixed footer structure. The ransomware drops a recovery note, renames encrypted files, attempts to clear the Recycle Bin, and can self-delete. It also contains functionality consistent with handling files locked by running processes. Researchers noted that interrupted encryption may leave recoverable key material in an intermediate footer state, whereas fully completed encryption requires access to runtime secret material or operator-controlled private keying for decryption.
At present, there is insufficient public evidence to confidently attribute M3rx to a previously known ransomware family, affiliate program, or nation-state sponsor. No corroborated intrusion pathway, parent organization, or stable overlap with an established crew has been confirmed. M3rx is best characterized as a newly observed financially motivated ransomware actor with active leak-site operations, cross-sector victimization, and a custom Go-based Windows encryptor.
Operational record
Recent claims
MITRE ATT&CK