donutleaks logo

donutleaks

1 incidentes 1 paises 0 sectores ransomware RU Ultimo: 2026-06-25
Ver en IntelTracker → APTTrail →
DonutLeaks is a data extortion and ransomware group that first emerged in August 2022, rapidly gaining attention for its aggressive tactics and significant data leaks. Initially operating as an affiliate for established threat groups like Hive and Ragnar Locker, DonutLeaks evolved to develop and deploy its own customized ransomware encryptor, marking a shift towards independent operations and more effective monetization of stolen data. The group's primary motivation is financial gain through double extortion, which involves stealing sensitive information and then encrypting systems or threatening to release the exfiltrated data if ransom demands are not met. What distinguishes DonutLeaks is its theatrical approach to extortion, characterized by unique graphics and humorous content in their ransom notes, and an adaptable operational model that has recently seen a trend towards focusing solely on data extortion without necessarily deploying encryption. The group is also known by the alia
Tecnicas MITRE
T1059.001, T1566.001, T1027, T1486, T1070.004

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

Greece (1)

Paises objetivo (SOCRadar)

ArgentinaCanadaGermanySpainUnited KingdomGreeceIrelandIran, Islamic Republic ofItalyRussian Federation

Sectores objetivo (SOCRadar)

Construction of BuildingsOther Information ServicesSoftware PublishersReal EstateManufacturingConstructionPublic AdministrationOil & GasEducational ServicesInternet Publishing

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com