// THREAT ACTOR
XPL0ITRS_
ActiveXPL0ITRS is a ransomware operator tracked through its public data-leak infrastructure. The group operates under the double-extortion model that defines the modern ransomware ecosystem — file encryption combined with the threat of stolen-data publication on a public leak site — and continues to post fresh victim claims as part of an ongoing extortion campaign.
For Ransomnews editorial coverage of XPL0ITRS — incident write-ups, attribution notes, and additional context — see the Threat Groups archive or run a site search.
Victims by year
- 2026 8
Leak site mirrors
1 mirror tracked, 1 currently reachable. These are criminal-infrastructure URLs — links are deliberately not provided.
-
2kieaq6jnwgrru62wwtxaafg35q6rzweg7y2xjfnbhvq5wd4eojqv6yd.onionxpl0itrs:~/psa snapshot · 2026-08-23 15:07
Recent victims
The 50 most recent victims claimed by XPL0ITRS. Total in the index: 8.
| Date listed | Victim | Description |
|---|---|---|
| 2026-08-20 | Gruppo Spaggiari Parma | School management software |
| 2026-08-20 | Target | General merchandise retail |
| 2026-08-19 | Mihuru | Consumer travel financing |
| 2026-08-17 | BMW Group | German multinational luxury vehicles |
| 2026-08-16 | Dynatrace | AI observability platform |
| 2026-08-16 | Oz Hair & Beauty | Hair and beauty products |
| 2026-08-16 | ********* | School management software |
| 2026-08-16 | RapidFort | Software supply chain security |