darkangels logo

darkangels

1 incidentes 0 paises 0 sectores ransomware RU Ultimo: 2026-06-25
Aliases: Dunghill Leak
Ver en IntelTracker → APTTrail →
Dark Angels is a financially motivated ransomware group that first launched attacks in April 2022, although its logo claims formation in 2021. The group has evolved from using Babuk-derived ransomware in its early operations to incorporating variants like RTM Locker and RagnarLocker for Windows and Linux/ESXi systems by mid-2023. Assessed with high confidence to operate from Russian-speaking regions, Dark Angels' primary motivation is significant financial gain through targeted extortion. What distinctly sets this group apart is its independent, "big game hunting" approach, focusing on a limited number of high-value enterprises rather than employing a widespread affiliate model. This strategy allows them to secure record-breaking ransoms, including a documented $75 million payment in 2024, while often minimizing public attention by selectively deploying encryption based on the potential for business disruption, frequently prioritizing massive data theft.
Tecnicas MITRE
T1059.001, T1078, T1486, T1566.001

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises objetivo (SOCRadar)

American SamoaBrazilCanadaChinaGermanyFranceUnited KingdomItalyJapanMexico

Sectores objetivo (SOCRadar)

Construction of BuildingsFood ManufacturingOther Information ServicesSoftware PublishersAir TransportationManufacturingConstructionElectrical Equipment, Appliance, and Component ManufacturingPublic AdministrationEducational Services

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com