exitium is a ransomware operator currently active on public leak sites. Darkfield has indexed 8 public victims claimed by this operator between March 17, 2026 and May 16, 2026. Exitium is an emerging ransomware group that was first observed in March 2026, operating with apparent financial motivations based on their limited but documented attack patterns. Given the recent emergence and limited public documentation, specific details about the group's country of origin, organizational structure, or potential affiliations remain unclear to security researchers and law enforcement agencies. The group's attack methodology and technical capabilities have not been extensively documented due to their recent appearance and small victim count, though they appear to target specific sectors rather than conducting widespread campaigns. Exitium has been observed targeting organizations in the United States and Brazil, with a particular focus on the agriculture and food production sector as well as public sector entities, suggesting possible strategic targeting of critical infrastructure. The group remains active as of their recent emergence, though their limited victim count of two documented cases indicates they are either highly selective in their targeting, newly operational, or operating at a smaller scale compared to established ransomware groups.
How we know this. Operator profiles on Darkfield are built from continuous monitoring of every leak site the group is known to operate, cross-correlated with community-curated feeds (RansomLook, ransomware.live, RansomWatch, MISP-galaxy). Status flips from active to inactive when no new disclosure appears for 60 days. MITRE ATT&CK mappings shown in the interactive section below are sourced from CISA, vendor analysis, and the MITRE community catalog — we attribute each technique back to its source. Aliases reflect operator re-brands and affiliate splits.