bravox
RansomwareAbout the group
BravoX is a selective ransomware-as-a-service operation that surfaced publicly in January 2026 after advertising on the RAMP underground forum, targeting primarily US-based organizations in healthcare and retail while applying strict affiliate vetting requirements including proof of access or a financial deposit.
Exploited vulnerabilities
No CVEs attributed to this group in public sources (MITRE ATT&CK). Absence of attribution does not mean absence of activity.
Impact and victims
The group bravox has 2 known ransomware victims. See the most affected sectors and countries and recent victims.
2known victims
2in Brazil
2sectors hit
Activity (12 months)
Most attacked sectors
Manufacturing1
Technology1
Most affected countries
🇧🇷 Brasil2
Recent victims
Meta
Grupo Mauá
bravox uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.
Explore the AI Autonomous Pentest →