donex logo

donex

1 incidentes 1 paises 0 sectores ransomware Ultimo: 2026-06-25
Aliases: fake LockBit 3.0, Muse, DarkRace
Ver en IntelTracker → APTTrail →
DoNex is a financially motivated ransomware group that first emerged in April 2022 under the name Muse, subsequently rebranding as fake LockBit 3.0 in November 2022, DarkRace in May 2023, and finally DoNex in March 2024. The group uses double extortion tactics, encrypting files and exfiltrating sensitive data to pressure victims into paying. They target enterprises primarily in the United States and Europe. A distinguishing characteristic is the cryptographic flaw in their encryptor, specifically its use of the Salsa20 stream cipher without generating a unique nonce or key for each file, which allowed for the development of a free decryptor by Avast and Computest Sector 7 in July 2024. Their motivation is purely financial, with ransom notes often stating they are not politically motivated.
Tecnicas MITRE
T1489, T1012, T1059.003, T1207, T1021.001, T1490

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United States (1)

Paises objetivo (SOCRadar)

BelgiumBrazilSwitzerlandCzech RepublicGermanyItalyNetherlandsPolandPortugalSweden

Sectores objetivo (SOCRadar)

Other Information ServicesEnterprises & HoldingManufacturingElectrical Equipment, Appliance, and Component ManufacturingPublic AdministrationAdministrative &Waste Management Educational ServicesWholesale TradeTextile & Fabric ManufacturingRestaurants

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com