darkvault logo

darkvault

1 incidentes 1 paises 1 sectores ransomware RU Ultimo: 2026-06-25
Ver en IntelTracker → APTTrail →
DarkVault is a ransomware group that emerged in November 2023, known for its diverse cybercriminal activities extending beyond ransomware to include bomb threats, swatting, doxing, website defacing, malware creation, scams, spam, and various forms of fraud. The group operates by maintaining an .onion site where they list alleged victims and advertise their illegal services. DarkVault employs a double extortion model, encrypting victim systems and subsequently threatening to leak stolen data if ransom demands are not met. While some have speculated about a connection to the LockBit ransomware group due to similarities in their data leak site design, there is no concrete evidence to confirm this, and DarkVault is largely regarded as a copycat. The group claims German origin, though this is likely a diversion, and key actors associated with DarkVault include individuals known by the monikers "criminaldo" and "Neroces".
Tecnicas MITRE
T1566.001, T1078, T1486, T1027

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United Kingdom (1)

Paises objetivo (SOCRadar)

AndorraUnited Arab EmiratesArgentinaBolivia, Plurinational State ofBrazilBelarusCanadaChinaGermanyUnited Kingdom

Sectores atacados

Finance (1)

Sectores objetivo (SOCRadar)

Food ManufacturingOther Information ServicesSoftware PublishersReal EstateHospitalsManufacturingPublic AdministrationEducational ServicesData Processing ServicesRestaurants

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com