PULSE NAME
Helldown Ransomware: an overview of this emerging threat
WHITE tr2222200 2024-11-21 Modified: 2024-11-21
13
IOCs
MEDIUM VOLUME
Helldown is a relatively new Intrusion Set in the ransomware landscape, first documented by Cyfirma in their August ransomware tracking report. Although still largely undocumented, the group is highly active, having listed 28 victims on its Data Leak Site (DLS) since 5 August 2024. While the group’s exact methods remain unclear, both Cyfirma and Cyberint reports that it exploits vulnerabilities to infiltrate victims’ networks and deploy its ransomware. The IS employs a double extortion strategy, exfiltrating large volumes of data and threatening to publish it on its .onion site if the ransom is not paid. The group’s DLS underwent changes toward the end of August. Notably, while the victims listed on the original DLS were transferred to the new one, three victims were removed. The reason for this removal is unclear, but it may indicate that a ransom was paid.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
darkrace Windows Linux Donex Helldown
Indicators of Compromise (13)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 4a4d03743fd3a7ee1d03d89d0e3b8011 MD5 of 2b15e09b98bc2835a4430c4560d3f5b25011141c9efa4331f66e9a707e2a23c0 2024-11-21
FileHash-SHA1 127d72408c87d866c72331fb0f16d13fef6a92ec SHA1 of 2b15e09b98bc2835a4430c4560d3f5b25011141c9efa4331f66e9a707e2a23c0 2024-11-21
FileHash-SHA256 2621c5c7e1c12560c6062fdf2eeeb815de4ce3856376022a1a9f8421b4bae8e1 2024-11-21
FileHash-SHA256 2b15e09b98bc2835a4430c4560d3f5b25011141c9efa4331f66e9a707e2a23c0 2024-11-21
FileHash-SHA256 3e3fad9888856ce195c9c239ad014074f687ba288c78ef26660be93ddd97289e 2024-11-21
FileHash-SHA256 47635e2cf9d41cab4b73f2a37e6a59a7de29428b75a7b4481205aee4330d4d19 2024-11-21
FileHash-SHA256 67aea3de7ab23b72e02347cbf6514f28fb726d313e62934b5de6d154215ee733 2024-11-21
FileHash-SHA256 6ef9a0b6301d737763f6c59ae6d5b3be4cf38941a69517be0f069d0a35f394dd 2024-11-21
FileHash-SHA256 7731d73e048a351205615821b90ed4f2507abc65acf4d6fe30ecdb211f0b0872 2024-11-21
FileHash-SHA256 7cd7c04c62d2a8b4697ceebbe7dd95c910d687e4a6989c1d839117e55c1cafd7 2024-11-21
FileHash-SHA256 9ab19741ac36e198fb2fd912620bf320aa7fdeeeb8d4a9e956f3eb3d2092c92c 2024-11-21
FileHash-SHA256 cb48e4298b216ae532cfd3c89c8f2cbd1e32bb402866d2c81682c6671aa4f8ea 2024-11-21
FileHash-SHA256 ccd78d3eba6c53959835c6407d81262d3094e8d06bf2712fefa4b04baadd4bfe 2024-11-21