Gammax — Ransomware Profile
Gammax is a financially motivated extortion crew first observed on its Tor-based data-leak site in July 2026; leak-site monitor ransomware.live indexed the operation on 30 July 2026 and shows at least four claimed victims through early August. WatchGuard's ransomware tracker classifies Gammax as an emerging crypto-ransomware operation running direct and double extortion plus free data leaks, and lists a Tox contact address. Claimed victims span the United States, Panama and Saudi Arabia across energy and utilities, professional services and retail, including Panamanian municipal-cleaning firm AguAseo per GalaxyWarden and, per DeXpose, US produce wholesaler King International LLC, listed on 6 August 2026 under a threat to publish a full leak. The listings remain unverified leak-site claims, and no vendor has yet publicly linked the group to specific tooling or affiliates.
Recent claimed victims
Read the full analysis on IntelFusions