Uptime Hamster: 21d 23h 16mDeploy: 3 Aug 2026 06:56Updated: 2026-07-21
Logo del actor de amenaza darkangels

darkangels

2 incidentes 1 paises 0 sectores threat-actor RU Ultimo: 2026-06-29
Aliases: Dunghill Leak
Ver en IntelTracker → APTTrail →
Dark Angels is a financially motivated ransomware group that first launched attacks in April 2022, although its logo claims formation in 2021. The group has evolved from using Babuk-derived ransomware in its early operations to incorporating variants like RTM Locker and RagnarLocker for Windows and Linux/ESXi systems by mid-2023. Assessed with high confidence to operate from Russian-speaking regions, Dark Angels' primary motivation is significant financial gain through targeted extortion. What distinctly sets this group apart is its independent, "big game hunting" approach, focusing on a limited number of high-value enterprises rather than employing a widespread affiliate model. This strategy allows them to secure record-breaking ransoms, including a documented $75 million payment in 2024, while often minimizing public attention by selectively deploying encryption based on the potential for business disruption, frequently prioritizing massive data theft.

Aliases del actor

Dunghill Leak

Actores similares

Dunghill Leakthreat-actor · 0worldleaksransomware · 167dataleakthreat-actor · 8leakbazaaractor · 8LeakBazaarthreat-actor · 2ValenciaLeaksthreat-actor · 2darkleakmarketthreat-actor · 2donutleaksthreat-actor · 2dunghillthreat-actor · 2leaktheanalystthreat-actor · 2

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / leak siteupransomware.anggipradana.comRansomware Group: darkangels
DLS / onionupwemo2ysyeq6km2nqhcrz63dkdhez3j25yw2nvn7xba2z4h7v7gyrfgid.oniondarkangels
DLS / onionofflinewemo2ysyeq6km2nqhcrz63dkdhez3j25yw2nvn7xba2z4h7v7gyrfgid.onionCTI.FYI
Tecnicas MITRE
T1059.001, T1078, T1486, T1566.001
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United States (1)

Paises objetivo (OSINT)

American SamoaBrazilCanadaChinaGermanyFranceUnited KingdomItalyJapanMexico

Sectores objetivo (OSINT)

Construction of BuildingsFood ManufacturingOther Information ServicesSoftware PublishersAir TransportationManufacturingConstructionElectrical Equipment, Appliance, and Component ManufacturingPublic AdministrationEducational Services

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com