bravox

Ransomware
Sourceransomware.live

About the group

BravoX is a selective ransomware-as-a-service operation that surfaced publicly in January 2026 after advertising on the RAMP underground forum, targeting primarily US-based organizations in healthcare and retail while applying strict affiliate vetting requirements including proof of access or a financial deposit.

Exploited vulnerabilities

No CVEs attributed to this group in public sources (MITRE ATT&CK). Absence of attribution does not mean absence of activity.

Impact and victims

The group bravox has 2 known ransomware victims. See the most affected sectors and countries and recent victims.

2known victims
2in Brazil
2sectors hit
Activity (12 months)
05
06
Most attacked sectors
Manufacturing1
Technology1
Most affected countries
🇧🇷 Brasil2
Recent victims
MetaTechnology · BR · 2026-06-23
Grupo MauáManufacturing · BR · 2026-05-31

bravox uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →