Skip to main content

Operator dossier

Pryx is a ransomware operator currently active on public leak sites. Darkfield has indexed 7 public victims claimed by this operator between May 15, 2026 and August 25, 2026. Auto-discovered from ransomware tracking sources

How we know this. Operator profiles on Darkfield are built from continuous monitoring of every leak site the group is known to operate, cross-correlated with community-curated feeds (RansomLook, ransomware.live, RansomWatch, MISP-galaxy). Status flips from active to inactive when no new disclosure appears for 60 days. MITRE ATT&CK mappings shown in the interactive section below are sourced from CISA, vendor analysis, and the MITRE community catalog — we attribute each technique back to its source. Aliases reflect operator re-brands and affiliate splits.

Active ransomware operator

All groups

Pryx

7 victims indexed · first seen 4 months ago · last activity 6 days ago

7
Victims indexed
#255 of 395 tracked operators
3m
Active period
May 2026 → Aug 2026
Countries hit

At a glance

Status
active
First seen
4 months ago
Last activity
6 days ago
Onion sites
3 known endpoints

About

Auto-discovered from ransomware tracking sources

Recent victims

Loading…

Onion infrastructure

3 known
  • http://c2mdhim6btaiyae3xqthnxsz64brvdxsnbty4tvos65zb565y4v55iid.onion
  • http://c2mdhim6btaiyae3xqthnxsz64brvdxsnbty4tvos65zb565y4v55iid.onion/b/
  • http://pryx.cc

Source

Updated 6 days ago

Data on this page is sourced from the group's own leak posts, cross-checked with public ransomware trackers (RansomLook, ransomware.live, RansomWatch), MITRE ATT&CK, and our own Tor and Telegram crawlers. This is a public observatory page — share freely.

Get alerted the next time Pryx posts a victim.

Add Pryx to your watchlist — Pro pings you within 5 minutes of any new Pryx leak-site post, Telegram callout, or affiliate-rebrand inference.