Bluebox is a recently emerged ransomware operation first observed in December 2024, appearing to be financially motivated based on typical ransomware monetization patterns. The group's origin and potential affiliations remain unclear due to its recent emergence, and it is unknown whether they operate as an independent entity or utilize a Ransomware-as-a-Service model. With only three documented victims across France and Sweden, primarily targeting business services and manufacturing sectors, the group's attack methodology, initial access vectors, and technical capabilities have not been extensively documented by major security research organizations. Due to the limited public reporting from established threat intelligence sources like CISA, FBI, or Mandiant, specific details about their encryption methods, extortion tactics, or notable campaigns cannot be confirmed. The group appears to remain active as of early 2024, though their operational scope and impact remain minimal compared to established ransomware families. The group has been linked to 3 public disclosures across our corpus. First observed on a leak site on December 11, 2024; most recent post December 17, 2024. The operation is currently inactive.
Sector and geography
This disclosure adds to ransomware activity in the Not Found sector, which has 4,859 disclosures indexed across all operators we track. Geographically, Groupe-fimar is reported in France, a country with 472 ransomware disclosures in our corpus.
How we know this. Darkfield monitors public ransomware leak sites continuously, archiving every new disclosure and the data later released against the victim. Each entry on this page is sourced from the operator's own publication and cross-checked against complementary OSINT feeds (RansomLook, ransomware.live, RansomWatch). We do not collect or host stolen data — only the metadata, timestamps and screenshots needed to make the public disclosure searchable and accountable. Records here are corrected when the original post is edited, retracted, or merged with another disclosure.