dunghill logo

dunghill

1 incidentes 0 paises 1 sectores ransomware RU Ultimo: 2026-06-25
Aliases: Dark Angels
Ver en IntelTracker → APTTrail →
Dunghill is a financially motivated ransomware group, active since at least early 2023 as a data leak site (DLS) for the Dark Angels Team, a group that itself emerged in April 2022. While the group claims activity since 2019, verifiable evidence points to the Dunghill Leak DLS beginning in early 2023, with a rebrand to Dunghill occurring in April 2023. This group distinguishes itself through ruthless tactics and extensive use of double extortion methods, aggressively targeting high-value organizations and critical infrastructure. They are known for demanding substantial ransoms, including a record-breaking $75 million payment in 2024. The Dunghill Leak DLS is specifically used to publicize stolen data from victims who refuse to negotiate or pay ransoms, showcasing their commitment to escalating pressure tactics. The group is considered a spin-off or rebrand of the Dark Angels ransomware, which is a derivative of the Babuk ransomware.
Tecnicas MITRE
T1059.001, T1078.003, T1047, T1021

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises objetivo (SOCRadar)

Bolivia, Plurinational State ofBrazilCanadaChinaGermanyUnited KingdomCroatiaIndiaMexicoNetherlands

Sectores atacados

Healthcare (1)

Sectores objetivo (SOCRadar)

Construction of BuildingsFood ManufacturingOther Information ServicesSoftware PublishersEnterprises & HoldingAir TransportationManufacturingConstructionElectrical Equipment, Appliance, and Component ManufacturingPublic Administration

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com