Ransomware Group intelligence
D1R
ActiveTrack D1R with 6 published victims and 1 known leak locations in a single intelligence view.
Overview
D1R is tracked by Breach House as a ransomware group with 6 published victims.
Germany is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Web location | Up checked 4h ago | dirone3rl3vvq64ckcnrvhe2ogrhjrwu5u7hqzrlotu3rfvmqmmbsuqd.onion/items |
Top Activity Sectors (2)
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue D1R, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1047 Windows Management Instrumentation Execution
What they do: D1R uses Windows Management Instrumentation to execute malicious commands and deploy ransomware components silently.
What that means: Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads.
-
T1059.001 PowerShell Execution
What they do: D1R executes malicious commands using PowerShell scripts to stage payloads and manipulate system behavior.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: D1R modifies Windows Registry Run keys to maintain persistence across reboots using hidden startup entries.
What that means: Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: D1R disables security tools by modifying Windows Defender and antivirus service configurations to evade detection.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: D1R deletes Volume Shadow Copies and recycle bins via vssadmin and command-line tools to prevent recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1083 File and Directory Discovery Discovery
What they do: D1R uses file and directory discovery via PowerShell to enumerate user data and identify encryption targets.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: D1R moves laterally through SMB/Windows Admin Shares using stolen credentials to access additional networked systems.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: D1R encrypts victim files using a custom ransomware algorithm targeting documents, images, and backups.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: D1R inhibits system recovery by corrupting restore points and disabling backup restoration mechanisms.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
-
T1491.001 Internal Defacement Impact
What they do: D1R performs internal defacement by appending ransom notes and altering file metadata across compromised systems.
What that means: An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems.
Victims (6)
Search, filter and paginate the victim timeline for D1R. Showing 1–6 of 6.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Bosch id30515 View details | Germany | Manufacturing / Engineering | — | |
|
Bosch.de is a leading German-based multinational engineering and technology company that operates in the manufacturing sector, offering a wide range of products and services. The company is headquartered in Gerlingen, Germany, and is known for its innovative solutions in areas such as automotive, industrial technology, and consumer goods. Bosch.de was listed as a ransomware victim associated with D1R |
|||||
| Ransomware | Bosch id30515 View details | Germany | Manufacturing / Engineering | — | |
|
Again, thanks to database Synopsys provided us with After analyzing technical leaks by other groups and cross-referencing targets from TARGETLIST.txt A company access was found and in the archives, a $10,000 gem: Bosch CAN module implementation Now it is going for free for every engineer and car enthusiast, thanks to Synopsys providing us with neat roadmap to tech sector Sorry, Bosch, you got third-partied! Call the Synopsys CEO and thank them for letting us all know where the valuable data is! |
|||||
| Ransomware | ARM id30516 View details | United Kingdom | IT | — | |
|
Arm.com is a leading technology company based in the United Kingdom, operating in the IT sector. The company designs and licenses intellectual property, including microprocessor architectures and related technologies. Arm.com was listed as a ransomware victim associated with D1R |
|||||
| Ransomware | ARM id30516 View details | United Kingdom | IT | — | |
|
Thanks to leaked database by Synopsys, a roadmap was provided Many other group leaks were cross-referenced and thoroughly analyzed One of the leaked companies gave our team access to ARM center Severely incapacitated by 2FA email/sms-code required by ARM on every step, we were still able to download an interesting tool: Athena Download Manager That requires an SSL certificate of a company that owns ARM products, and downloading by means of Athena allows to bypass multiple 2FA checks that are required when downloading same files from www.arm.com This is now free for download to any reverse engineer on Earth and beyond, thanks to Synopsys company data negligence: |
|||||
| Ransomware | Synopsys id30517 View details | United States | IT | — | |
|
Synopsys.Com is a leading American technology company operating in the IT sector, providing software and services to various industries. The company is headquartered in the United States and offers a range of products and solutions, including software security and quality solutions. Synopsys.Com was listed as a ransomware victim associated with D1R |
|||||
| Ransomware | Synopsys id30517 View details | United States | IT | — | |
|
Data, Leak |
|||||