PULSE NAME
Helldown Ransomware: an overview of this emerging threat
WHITE tr2222200 2024-11-21 Modified: 2024-11-21
13
IOCs
MEDIUM VOLUME
Helldown is a relatively new Intrusion Set in the ransomware landscape, first documented by Cyfirma in their August ransomware tracking report. Although still largely undocumented, the group is highly active, having listed 28 victims on its Data Leak Site (DLS) since 5 August 2024. While the group’s exact methods remain unclear, both Cyfirma and Cyberint reports that it exploits vulnerabilities to infiltrate victims’ networks and deploy its ransomware. The IS employs a double extortion strategy, exfiltrating large volumes of data and threatening to publish it on its .onion site if the ransom is not paid. The group’s DLS underwent changes toward the end of August. Notably, while the victims listed on the original DLS were transferred to the new one, three victims were removed. The reason for this removal is unclear, but it may indicate that a ransom was paid.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
darkrace Windows Linux Donex Helldown
Indicators of Compromise (1 / 13 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 127d72408c87d866c72331fb0f16d13fef6a92ec SHA1 of 2b15e09b98bc2835a4430c4560d3f5b25011141c9efa4331f66e9a707e2a23c0 2024-11-21