M3rx — Ransomware Profile

M3rx is a ransomware group first observed in April 2026 that operates a data leak site and uses a Tox ID as its victim contact channel. Reverse engineering of a Windows PE32+ x64 encryptor written in Go, linked to the group by the contact details in its ransom note, found per-run X25519 key exchange, AES-CTR encryption of file content and AES-GCM wrapping of each per-file key, with the encryptor writing a note named RECOVERY_NOTES.TXT and deleting itself through PowerShell. Symantec's protection bulletin of 28 May 2026 independently reports the same X25519 key exchange, AES file encryption, random eight-character extension, RECOVERY_NOTES.TXT note and PowerShell self-deletion. IntelFusions has recorded 36 victim listings claimed by the group between 29 April and 26 July 2026, spanning organizations in North America, Europe and Australia. No public evidence has tied M3rx to a known crew or affiliate toolkit, and while Symantec maps its initial access to external remote services and valid accounts, no intrusion has been documented in public in detail.

IntelFusions coverage (1)

Tools & malware

Recent claimed victims

Vendor research

Read the full analysis on IntelFusions