Gammax surfaced on tracker radar just a week ago and has already claimed five victims, with Saudi Arabia as its apparent center of gravity (three claims, including overlapping entries tied to Mahmoud Altaheni & Partners Trading Co) alongside single claims in the US and Colombia. The sector spread is narrow and opportunistic: professional services, an energy/utilities operator, and entries logged simply as "Other," suggesting the group is not yet specializing but testing across industries. No MITRE ATT&CK technique set has been catalogued for this actor, and no group description is on file, so claims about its tooling or intrusion methods cannot be verified. All victim identifications and sector/country attributions here reflect the group's own leak-site claims, not confirmed compromises. Given the short operating window and small claim count, Gammax reads at this stage as a new or rebranded entrant still establishing a pattern rather than an established, high-volume operation.