Skip to content

xpl0itrs

xpl0itrs is a ransomware-linked cybercriminal threat actor observed conducting attacks against organizations in the United States and Australia.

Profile source: Mallory opens in a new tab

xpl0itrs

Family profile

xpl0itrs is a ransomware-linked cybercriminal threat actor observed conducting attacks against organizations in the United States and Australia. Reported victims include a U.S.-based technology company and an Australian retail and e-commerce company, indicating opportunistic targeting across multiple sectors rather than a narrowly specialized victimology. The group has been associated with ransomware incidents that were also characterized as data breaches, supporting assessment of extortion-oriented operations involving data theft.

xpl0itrs has also been reported as cooperating with other criminal actors, including TeamPCP, with indirect association to DarkRomance and a ShinyHunters-branded extortion cluster linked to Scattered Lapsus$ Hunters. This suggests participation in a broader cybercrime ecosystem where access, stolen data, and extortion capabilities may be shared or coordinated across groups. Publicly available facts in this context support classifying xpl0itrs as a financially motivated ransomware actor with extortion capability, but do not provide high-confidence detail on its malware lineage, internal structure, or country of origin.

Operational record

Recent claims

MITRE ATT&CK

xpl0itrs in ATT&CK

1 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.