News Room
16
Share
Chaos and M3rx Ransomware Groups Escalate Attacks on US Healthcare and Legal Sectors
criticalThreat Intelligence

Chaos and M3rx Ransomware Groups Escalate Attacks on US Healthcare and Legal Sectors

As of September 30, 2026, the Chaos and M3rx ransomware groups have launched targeted double-extortion campaigns against US-based organizations, threatening the release of hundreds of gigabytes of sensitive data.

30 September 2026Last updated 30 September 20264 min readDexpose Intel Feeds
E
Encrygma AI Cyber Weapons Advisory Services :We sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Threat Intelligence
Severity:
Critical
Actor Type:
Ransomware Group
Geography:
USA
Confidence:
Confirmed
Source:
Dexpose Intel Feeds
Read Time:
4 min

Executive Summary

On September 30, 2026, intelligence feeds confirmed a surge in aggressive ransomware activity targeting critical infrastructure in the United States. The Chaos ransomware group has initiated a high-pressure campaign against the Carolina Asthma & Allergy Center, while the M3rx group has successfully breached the South Florida law firm Otero Geeza Law, P.A. Both incidents utilize classic double-extortion tactics, where threat actors exfiltrate sensitive data before encrypting systems to force payment.

Threat Analysis

The current landscape reflects a shift toward rapid-fire extortion. The Chaos group has issued a 24-hour ultimatum to the Carolina Asthma & Allergy Center, threatening to leak 290 GB of patient and administrative records. Simultaneously, M3rx has claimed the theft of 82.5 GB of data from Otero Geeza Law, P.A. These attacks highlight a persistent trend where threat actors prioritize the exfiltration of personally identifiable information (PII) and protected health information (PHI) to maximize leverage over victims who are legally obligated to protect such data.

Technical Details

Both groups are employing sophisticated multi-stage attack chains. Initial access is frequently gained through credential harvesting or the exploitation of unpatched edge-facing vulnerabilities. Once inside the network, the actors move laterally to identify backup servers. Recent reports indicate that emerging gangs are increasingly prioritizing the destruction of backups to eliminate the possibility of recovery without paying the ransom. The exfiltration phase involves the use of automated tools to siphon data to cloud storage providers, followed by the deployment of custom encryption binaries that bypass traditional signature-based detection.

Attribution Assessment

Chaos and M3rx are identified as cybercriminal syndicates operating with a focus on financial gain. While their infrastructure is often obfuscated through multi-hop proxies, their operational patterns—specifically the use of public leak sites to host stolen data—align with established Ransomware-as-a-Service (RaaS) models. These groups are likely composed of distributed affiliates who leverage shared malware kits to conduct independent campaigns.

Implications

The targeting of healthcare and legal entities suggests a strategic focus on sectors with low tolerance for downtime and high regulatory pressure regarding data privacy. The 24-hour deadline imposed by the Chaos group is particularly concerning, as it leaves minimal time for incident response teams to contain the breach or negotiate, effectively forcing a binary choice between payment and public data exposure.

Recommendations

Organizations must prioritize the implementation of immutable, off-site backups that are air-gapped from the primary network. Furthermore, security teams should enforce strict multi-factor authentication (MFA) across all remote access points and conduct regular threat hunting exercises to identify indicators of compromise (IoCs) associated with RaaS affiliates. Given the rapid escalation of these attacks, incident response plans should be updated to include pre-negotiated legal and forensic support to handle extortion demands effectively.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo