axxes
- First seen
- 2023-01-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Profile updated
- 2026-07-07 13:56:27
Targeted industries: retail-and-hospitality
Targeted regions: country_code:us country_code:ae country_code:fr country_code:cn
Context
Axxes ransomware emerged as a rebranded version of the previously known Midas ransomware group, with roots also tracing back through Haron and Avaddon lineage. It operates via a single-extortion model, encrypting files and appending the .axxes extension. Victims receive both an “RESTORE_FILES_INFO.hta” and a “.txt” ransom note. The ransomware performs extra actions like determining the device’s geolocation, modifying the Windows Firewall, changing file extensions, and terminating processes using taskkill.exe. Its known targets span the U.S., UAE, France, and China, including at least one high-profile victim—The H Dubai hotel. This group appears financially motivated, leveraging historical branding and code of earlier groups for its operations.
Reports & references
- ransomlook.io — Axxes (report)
- cloudsek.com — Axxes Ransomware Group Appears To Be The Rebranded Version Of Midas Group (report)
- hivepro.com — New Ransomware Group Axxes Is On The Rise Ta2022106 (report)
- bleepingcomputer.com — The Week In Ransomware April 29Th 2022 New Operations Emerge (report)