Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
S-RM

S-RM Vendor Cyber Rating & Cyber Score

s-rminform.com

S-RM is a global intelligence and cyber security consultancy. Founded in 2005, we have 400+ practitioners spanning nine international offices, serving clients across all regions and major sectors. We support our clients by providing intelligence that informs critical decision-making and strategies, from investments and partnerships through to disputes; by helping organisations build resilience to cyber security threats; and by responding to cyber-attacks and organisational crises. Client focus is at the heart of what we do. Our advice is direct, honest and objective. We deliver actionable results for our clients by bringing together the best talent and creating teams designed to address unique problems and complex challenges. For more


S-RM A.I CyberSecurity Scoring

S-RM
Company Information
Website:https://www.s-rminform.com
Employees number:375
Number of followers:49,118
NAICS:5616
Industry Type:Security and Investigations
Homepage:s-rminform.com
S-RM Risk Score (AI oriented)
Between 0 and 549
logo
S-RMSecurity and Investigations
Updated:
31/03/2026
543/1000
Critical
C
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
S-RM Global Score (TPRM)
xxxx
logo
S-RMSecurity and Investigations
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

S-RM
S-RMCritical
Current Score
543C (CRITICAL)
01000
2 incidents
-147 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
558Before Incident
MAY 2026
552Before Incident
APRIL 2026
548Before Incident
MARCH 2026
539Before Incident
FEBRUARY 2026
538Before Incident
JANUARY 2026
532Before Incident
DECEMBER 2025
668Before Incident
Ransomware
05 Dec 2025S-RM
S-RM: Critical React2Shell flaw exploited in ransomware attacks

Weaxor Ransomware Attack via React2Shell Vulnerability

521After Incident
HIGH-147
S-R1765994181
Weaxor Ransomware Exploits React2Shell Vulnerability in Rapid Attacks A ransomware gang leveraged the critical React2Shell vulnerability (CVE-2025-55182) to breach corporate networks and deploy Weaxor ransomware in under a minute. The flaw, an insecure deserialization issue in React Server Components (RSC) and Next.js, allows unauthenticated remote code execution on vulnerable servers. First disclosed in late 2024, React2Shell quickly became a target for both nation-state hackers—deploying cyberespionage tools like EtherRAT—and cybercriminals, who used it for cryptocurrency mining. On December 5, researchers at S-RM observed the Weaxor ransomware operation exploiting the vulnerability in a real-world attack. Weaxor, a rebrand of the Mallox/FARGO ransomware (active since 2024), is a low-complexity operation targeting public-facing servers with opportunistic attacks. Unlike more advanced ransomware groups, it does not exfiltrate data or use double-extortion tactics, instead demanding relatively modest ransoms. The attack unfolded rapidly: - Initial access via React2Shell was followed by an obfuscated PowerShell command deploying a Cobalt Strike beacon for command-and-control (C2). - The threat actor disabled Windows Defender’s real-time protection before executing the ransomware payload. - Encrypted files received the .WEAX extension, with ransom notes (RECOVERY INFORMATION.txt) left in affected directories. - The attackers wiped volume shadow copies and cleared event logs to hinder recovery and forensic analysis. Notably, the breach remained contained to the vulnerable endpoint, with no observed lateral movement. However, the same compromised host was later targeted by additional attackers, underscoring the high demand for React2Shell exploits. S-RM researchers recommend monitoring for suspicious process creation—particularly cmd.exe or PowerShell spawned from node.exe—as well as unusual outbound connections, disabled security tools, and log tampering. While patching is critical, defenders should also review EDR telemetry for signs of exploitation.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gain
IMPACT
Systems Affected: Public-facing servers, vulnerable endpointsOperational Impact: File encryption, system disruption
NOVEMBER 2025
668Before Incident
OCTOBER 2025
667Before Incident
SEPTEMBER 2025
665Before Incident
AUGUST 2025
663Before Incident
JULY 2025
661Before Incident
MARCH 2025
761Before Incident
Ransomware
01 Mar 2025S-RM
S-RM

Sophisticated Ransomware Attack on S-RM

651After Incident
CRITICAL-110
S-R226031025
S-RM encountered a sophisticated ransomware attack initiated by the Akira group, involving the exploitation of IoT devices, specifically an insecure webcam, to bypass EDR tools and encrypt files on the network. This innovative tactic allowed the attackers to overcome security measures and establish persistent access through AnyDesk.exe and lateral movement via RDP. The incident required a response team to address the breach and implement new security strategies. The data exfiltration and encryption caused considerable disruption to the company's operations, likely affecting its finances and reputation due to the sophisticated nature of the attack.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gain and data exfiltration
IMPACT
Operational Impact: Considerable disruptionBrand Reputation Impact: Likely affected

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for S-RM ?
?
What was S-RM's A.I Rankiteo Cyber Score in May 2026 ?
?
What was S-RM's A.I Rankiteo Cyber Score in April 2026 ?
?
What was S-RM's A.I Rankiteo Cyber Score in March 2026 ?
?
What was S-RM's A.I Rankiteo Cyber Score in February 2026 ?
?
What was S-RM's A.I Rankiteo Cyber Score in January 2026 ?
?
What was S-RM's A.I Rankiteo Cyber Score in December 2025 ?
?
What was S-RM's A.I Rankiteo Cyber Score in November 2025 ?
?
What was S-RM's A.I Rankiteo Cyber Score in October 2025 ?
?
What was S-RM's A.I Rankiteo Cyber Score in September 2025 ?
?
What was S-RM's A.I Rankiteo Cyber Score in August 2025 ?
?
What was S-RM's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on S-RM's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with S-RM ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view S-RM's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
S-RM Cyber Scoring History | Rankiteo