Xing Team
Attribution profile
- Type
- Criminal
- Location
- China
- Known incidents
- 4 incidents
- Sources
- 2 sources
- First seen
- 2021-04-01
- Last seen
- 2021-06-03
- Updated
- 2026-07-31 03:15
- Aliases
- 1 alias
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Xing Team, also known simply as Xing Team, is a ransomware group that has been observed operating since at least early 2021 and is noted in open‑source reporting to be based in China. The group identifies itself with a Chinese character meaning “star” on its dark‑web leak site, although researchers have noted that the name alone does not confirm a Chinese origin. Xing Team operates as a ransomware‑as‑a‑service affiliate, deploying a rebranded version of the Mount Locker ransomware to encrypt victims’ files. After encryption, the actors exfiltrate sensitive data and threaten to publish the stolen information on their leak site unless a ransom is paid. This double‑extortion model defines their primary extortion tactic.
Publicly attributed incidents show that Xing Team primarily targets healthcare organizations and companies that provide technology services to critical infrastructure. In mid‑2021 the group attacked OSF Healthcare in Illinois, GlobeMed Saudi in Saudi Arabia, and Coastal Family Health Center in Mississippi, exfiltrating hundreds of gigabytes of patient records, employee data, financial documents and internal communications. A month earlier they compromised LineStar Integrity Services, a Houston‑based provider of pipeline auditing, compliance and industrial‑control‑system software, stealing approximately 70 GB of emails, contracts, source code and human‑resources files. These incidents demonstrate a pattern of focusing on sectors that hold sensitive personal or operational data, with victims located in the United States and Saudi Arabia. The group’s stated goal in each case is to obtain payment by threatening to leak the stolen data, indicating a financially motivated extortion strategy.
Observed tactics, techniques and procedures include the deployment of a modified Mount Locker ransomware variant to encrypt files after prior data exfiltration, followed by the posting of the stolen material on a dark‑web leak site to pressure victims into paying. The group has been observed using the leak site to publish unredacted files, while third‑party transparency groups sometimes re‑publish redacted versions to limit exposure of personally identifiable information. No specific initial‑access vectors such as phishing emails or vulnerability exploits are described in the available sources, so the exact intrusion method remains unspecified in the public record. Attribution beyond the group’s self‑identified name and the open‑source note that it originates from China is not publicly established, and no links to state sponsorship or larger criminal syndicates have been demonstrated in the reporting. Consequently, the public profile of Xing Team is defined by its ransomware operations, data‑theft extortion, and targeting of healthcare and infrastructure‑service providers.
Incidents
Attributed incidents are available to members.
4 incidentsSources
Sources available to members: 2 sources.