AusProof Hit by M3rx Ransomware Gang, 460GB of Data Allegedly Stolen
Australian mining equipment manufacturer AusProof has been targeted by the M3rx ransomware gang, which claims to have exfiltrated 460GB of data approximately 373,495 files from the company’s systems. The firm, based in Gladstone, Queensland, specializes in electrical cable couplers for the mining and tunneling industries and has served global clients since its founding in 1994.
M3rx listed AusProof on its dark web leak site, though it has not disclosed a ransom demand or a timeline for releasing the stolen data. The group provided a file list as proof of the breach but offered no further details on the attack’s execution or scope. Cyber Daily has contacted AusProof for additional information, but no official response has been reported.
Who is M3rx?
Emerging in April–May 2024, M3rx is a relatively new ransomware operation targeting organizations across Australia, the U.S., England, Germany, Italy, and Switzerland. Security researchers at IBM X-Force Exchange have analyzed its ransomware variant, noting key technical traits:
- Uses a PE32+ x64 Go-based executable with an embedded configuration.
- Drops a ransom note (RECOVERY_NOTES.TXT) and appends the .8hmlsewu extension to encrypted files.
- Employs X25519 key exchange, AES-CTR for file encryption, and AES-GCM to secure per-file keys.
- Deletes itself via PowerShell post-execution and clears the Recycle Bin.
- Threatens data publication if ransom negotiations conducted in Bitcoin fail.
In May 2024, M3rx claimed responsibility for an attack on Prime Properties, a property investment firm, alleging the theft of 100GB of data (81,000+ files). The group’s tactics and infrastructure remain under investigation as its victim list grows.
Source: https://www.cyberdaily.au/security/13968-exclusive-ausproof-allegedly-breached-by-m3rx-ransomware
AusProof TPRM report: https://www.rankiteo.com/company/ausproof-pty-ltd
Prime Properties TPRM report: https://www.rankiteo.com/company/prime-equipment-group
"id": "auspri1785277842",
"linkid": "ausproof-pty-ltd, prime-equipment-group",
"type": "Ransomware",
"date": "5/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Mining equipment manufacturing',
'location': 'Gladstone, Queensland, Australia',
'name': 'AusProof',
'type': 'Company'}],
'data_breach': {'data_encryption': 'Yes (AES-CTR, AES-GCM)',
'data_exfiltration': 'Yes',
'number_of_records_exposed': '373,495 files'},
'description': 'Australian mining equipment manufacturer AusProof has been '
'targeted by the M3rx ransomware gang, which claims to have '
'exfiltrated 460GB of data (approximately 373,495 files) from '
'the company’s systems. The group listed AusProof on its dark '
'web leak site but has not disclosed a ransom demand or '
'timeline for releasing the stolen data.',
'impact': {'data_compromised': '460GB (373,495 files)'},
'investigation_status': 'Ongoing',
'motivation': 'Financial gain (ransom)',
'ransomware': {'data_encryption': 'Yes (.8hmlsewu extension)',
'data_exfiltration': 'Yes (460GB)',
'ransomware_strain': 'M3rx'},
'references': [{'source': 'Cyber Daily'}, {'source': 'IBM X-Force Exchange'}],
'threat_actor': 'M3rx ransomware gang',
'title': 'AusProof Hit by M3rx Ransomware Gang, 460GB of Data Allegedly '
'Stolen',
'type': 'Ransomware'}