BravoX is a selective ransomware-as-a-service operation that surfaced publicly in January 2026 after advertising on the RAMP underground forum, targeting primarily US-based organizations in healthcare and retail while applying strict affiliate vetting requirements including proof of access or a financial deposit.
Genera un perfil del actor con IA (defensivo) cuando lo pidas.
Este grupo no tiene TTPs curadas. Puedes generar un mapeo MITRE ESTIMADO por IA (no confirmado) a partir de su descripción/notas, solo cuando lo pidas.
Firma de detección defensiva para este grupo (úsala en tu EDR/SIEM). Fuente: ransomware.live.
/*
bravox ransomware
*/
rule bravox_Ransomnote
{
meta:
author = "ransomware.live"
family = "ransomware.bravox"
description = "Detects bravox ransomware ransom note or artifact"
date = "2026-05-04"
severity = 7
score = 70
strings:
$name1 = "bravox" ascii nocase
$name2 = "BRAVOX" ascii
$onion = "bravox.onion" ascii nocase
condition:
any of them
}
Operates in the construction, real estate, energy, and infrastructure sectors.
They research and promote policy and innovations in healthcare.
| Organización | País | Sector | Grupo | Descubierta |
|---|---|---|---|---|
| Grupo Mauá | BR | Manufacturing | — | 31 may 2026 |
| AcademyHealth | US | Healthcare | — | 29 may 2026 |
| Rivadeneyra Treviño | MX | Not Found | — | 12 may 2026 |
Las direcciones de los sitios de filtración (.onion) se conocen pero no se publican ni se enlazan. Solo se muestran metadatos públicos. ética
Rivadeneyra Treviño provides expert corporate legal advice, specializing in regulatory law, contract law, foreign trade, and intellectual property for national and international clients.