dAn0n logo

dAn0n

0 incidentes 0 paises 0 sectores ransomware Ultimo: -
Ver en IntelTracker → APTTrail →
dAn0n is a financially motivated cyber extortion group that first emerged in the spring of 2024, distinguishing itself by initially operating as a data broker rather than deploying traditional ransomware encryption. The group specialized in exfiltrating sensitive data and subsequently using aggressive public pressure tactics to coerce victims into paying ransoms for the data's return and to prevent its public release. This unique approach involved a detailed, multi-step extortion process tracked via a graphical user interface on their data leak site, informing various stakeholders such as leadership, insurance companies, clients, and regulatory authorities. Although their operations under the dAn0n name ceased in late August 2024 after publishing 19 victims, the group reportedly reappeared in 2025 as 'White Lock', which transitioned to utilizing traditional crypto-ransomware.
Tecnicas MITRE
T1566.001, T1078, T1059.001, T1490, T1486

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Tipo
ransomware
Pais origen
-
Motivacion
-
Impacto
39
Actualizado
Sat, 20 Ju

Paises objetivo (SOCRadar)

HungaryIrelandKorea, Republic ofNew CaledoniaUnited States

Sectores objetivo (SOCRadar)

Construction of BuildingsOther Information ServicesSoftware PublishersReal EstateHospitalsEnterprises & HoldingAccommodationManufacturingConstructionElectrical Equipment, Appliance, and Component Manufacturing