M3rx is a small ransomware group active since 2025, known for using AES encryption primarily.
Analyst brief
M3rx is a small ransomware group first observed in 2025. They primarily target Professional Services, Manufacturing, and Technology sectors across the US, Germany, Brazil, and Australia. Their main TTP involves AES-CTR/AES-GCM encryption and they have claimed around eight victims so far. Defenders should focus on ransomware prevention measures and monitor for encryption-related TTPs targeting these specific industries.
m3rx
activecrime
M3rx is a small ransomware group first observed in 2025, using AES-CTR/AES-GCM encryption and targeting organizations in England, the US, Australia, Germany, Italy, and Switzerland, with around eight claimed victims including a Sydney-based property firm.
observed victims (by country)
United StatesGermanyCanadaBrazil
observed sectors
Professional ServicesManufacturingTechnologyTransportation