Xpl0itrs — Ransomware Profile

Xpl0itrs is a financially motivated crew active since at least early 2026 that attacks the software supply chain rather than the organisations it ultimately reaches. Dataminr describes it as self-consciously commercial, keeping separate personas for ideological activity, and reports its closest partnership is with TeamPCP, with jointly claimed operations including the CanisterWorm campaign and the compromise of the Bitwarden CLI in April 2026. Its targets are the tools developers trust: Trivy, Checkmarx KICS, LiteLLM and Bitwarden CLI have all featured in campaigns attributed to the pair. The method is credential rather than malware led. It steals personal access tokens, OAuth tokens, API keys and CI/CD credentials, sells them as an initial access broker, and separately extorts the victims it keeps for itself, which means one vendor compromise converts into leverage over every downstream customer of that vendor. The group announced a dedicated leak site on 17 June 2026, an escalation from ad-hoc forum sales toward structured extortion, and its most publicly vocal member posts as boxturtl. Its claims run well ahead of its confirmations and both matter. Between 17 and 25 June 2026 it named Spotify, the US Department of the Treasury, OpenAI and Trustpilot on X; none of those organisations has confirmed anything, and the claims remain unverified. Our own log records three victims named on 15 August 2026: an Austrian observability vendor, a US software supply-chain security firm and an Australian retailer. For the first it claims roughly 246 Git repositories obtained through a compromised developer access token, about 8.46 GB covering more than 164,000 source files; for the second it claims 569 GB and 140,061 files pulled from 48 cloud storage buckets, including cloud credentials and defence-affiliated material. Neither company has confirmed the claim. Read every figure here as the attacker's assertion, quoted because the specificity is itself intelligence about what it wants buyers to believe.

Also tracked as

xpl0itrs

Recent claimed victims

Vendor research

Read the full analysis on IntelFusions