PULSE NAME
Helldown Ransomware: an overview of this emerging threat
WHITE Helldown AlienVault 2024-11-20 Modified: 2024-11-21
16
IOCs
MEDIUM VOLUME
Helldown is a new and highly active ransomware group that has claimed 31 victims in three months. It employs custom ransomware for Windows and Linux systems, engages in double extortion, and exploits vulnerabilities in Zyxel firewalls for initial access. The group exfiltrates large volumes of data, averaging 70GB per victim. Its Windows ransomware shares similarities with Darkrace and Donex variants. The Linux variant targets VMware ESX servers. While connections to other groups like Hellcat are unconfirmed, Helldown's success seems to rely on exploiting undocumented vulnerabilities rather than sophisticated malware. The group's rapid evolution and targeting of virtualized infrastructures make it a significant emerging threat.
Indicators of Compromise (16)
All CVE FileHash-MD5 FileHash-SHA1 FileHash-SHA256
TYPEINDICATORDESCRIPTIONCREATED
CVE CVE-2024-42057 2024-11-20
FileHash-MD5 4a4d03743fd3a7ee1d03d89d0e3b8011 2024-11-20
FileHash-SHA1 127d72408c87d866c72331fb0f16d13fef6a92ec 2024-11-20
FileHash-SHA256 0bfe25de8c46834e9a7c216f99057d855e272eafafdfef98a6012cecbbdcfabf 2024-11-20
FileHash-SHA256 2621c5c7e1c12560c6062fdf2eeeb815de4ce3856376022a1a9f8421b4bae8e1 2024-11-20
FileHash-SHA256 2b15e09b98bc2835a4430c4560d3f5b25011141c9efa4331f66e9a707e2a23c0 2024-11-20
FileHash-SHA256 3e3fad9888856ce195c9c239ad014074f687ba288c78ef26660be93ddd97289e 2024-11-20
FileHash-SHA256 47635e2cf9d41cab4b73f2a37e6a59a7de29428b75a7b4481205aee4330d4d19 2024-11-20
FileHash-SHA256 67aea3de7ab23b72e02347cbf6514f28fb726d313e62934b5de6d154215ee733 2024-11-20
FileHash-SHA256 6ef9a0b6301d737763f6c59ae6d5b3be4cf38941a69517be0f069d0a35f394dd 2024-11-20
FileHash-SHA256 7731d73e048a351205615821b90ed4f2507abc65acf4d6fe30ecdb211f0b0872 2024-11-20
FileHash-SHA256 7cd7c04c62d2a8b4697ceebbe7dd95c910d687e4a6989c1d839117e55c1cafd7 2024-11-20
FileHash-SHA256 9ab19741ac36e198fb2fd912620bf320aa7fdeeeb8d4a9e956f3eb3d2092c92c 2024-11-20
FileHash-SHA256 b83e8ff6d046dccad0f5a2777f067bdc8eb3b239c030165daf32f9dae902d012 2024-11-20
FileHash-SHA256 cb48e4298b216ae532cfd3c89c8f2cbd1e32bb402866d2c81682c6671aa4f8ea 2024-11-20
FileHash-SHA256 ccd78d3eba6c53959835c6407d81262d3094e8d06bf2712fefa4b04baadd4bfe 2024-11-20