Ransomware Group intelligence
Daixin
InactiveTrack Daixin with 35 published victims and 2 known leak locations in a single intelligence view.
Overview
Daixin is tracked by Breach House as a ransomware group with 35 published victims.
United States is currently the most targeted country in this dataset.
2 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (2)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 2 | Onion service | Up checked 1h ago | 7ukmkdtyxdkdivtjad57klqnd3kdsmq6tp45rrsxqnu76zzv3jvitlqd.onion |
| Leak location 1 | Onion service | Down checked 1h ago | 232fwh5cea3ub6qguz3pynijxfzl2uj3c73nbrayipf3gq25vtq2r4qd.onion |
Top Activity Sectors (10)
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Daixin, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: daixin executes PowerShell scripts to stage payloads and manipulate system processes during initial compromise.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: daixin disables antivirus tools and modifies security software to evade detection and persistence mechanisms.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1688 Safe Mode Boot Defense Impairment
What they do: daixin manipulates Safe Mode Boot settings to ensure persistence and hinder forensic analysis.
What that means: Adversaries may abuse Windows safe mode to disable endpoint defenses.
-
T1070.004 File Deletion Stealth
What they do: daixin deletes Volume Shadow Copies and backup directories via vssadmin to prevent data recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1110 Brute Force Credential Access
What they do: daixin brute-forces local accounts to gain initial access and persistence within victim networks.
What that means: Adversaries may use brute force techniques to gain access to accounts when passwords are unknown or when password hashes are obtained.
-
T1049 System Network Connections Discovery Discovery
What they do: daixin queries system network connections to identify high-value targets for lateral movement and exfiltration.
What that means: Adversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network.
-
T1057 Process Discovery Discovery
What they do: daixin uses process discovery to identify critical services and processes for targeted disruption or evasion.
What that means: Adversaries may attempt to get information about running processes on a system.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: daixin exploits SMB/Windows Admin Shares to move laterally across networked servers and workstations.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: daixin encrypts victim files using custom ransomware binaries targeting critical healthcare and financial data.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: daixin calls system recovery inhibitors to disable backup restoration mechanisms and maximize impact.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Tools Observed (1)
▼Software Daixin has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Exfiltration
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Victims (35)
Search, filter and paginate the victim timeline for Daixin. Showing 1–35 of 35.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | SGS Co id22289 View details | United States | Communication / Marketing | — | |
|
Brand design and packaging solutions agency. |
|||||
| Ransomware | Communicare Inc. id22288 View details | United States | Communication / Marketing | — | |
|
Communicare, Inc. has been a premier provider of behavioral health services in Kentucky's heartland since 1967. |
|||||
| Ransomware | Insurance Office of America id22287 View details | United States | Finance / Legal / Insurance | — | |
|
Insurance Office of America (IOA) is a premier, full-service insurance agency dedicated to delivering bespoke insurance solutions since 1988. We’re one of the USA’s fastest-growing agencies. |
|||||
| Ransomware | Gagosian id22286 View details | United States | Public Sector | — | |
|
Established by Larry Gagosian in Los Angeles in 1980, Gagosian is a global gallery specializing in modern and contemporary art that employs more than three hundred people at eighteen exhibition spaces across the United States, Europe, and Asia. |
|||||
| Ransomware | Acadian Ambulance (US) id13469 View details | United States | Healthcare / Pharma | — | |
|
acadianambulance.com is the website of Acadian Ambulance Service, an employee-owned private ambulance and medical transport provider based in Louisiana, United States. The company offers emergency and non-emergency patient transport, critical care transport, and related healthcare and support services across a multi-state service area, with operations in Louisiana, Texas, Tennessee, and Mississippi. Its site also includes patient billing, records, and contact resources for customers and referring facilities. In threat-intelligence catalogs, acadianambulance.com was listed as a ransomware victim associated with daixin. |
|||||
| Ransomware | Acadian Ambulance id22284 View details | United States | Healthcare / Pharma | — | |
|
Acadian Ambulance is an employee-owner private ambulance service that covers most of the state of Louisiana, a large portion of Texas, two counties in Tennessee, and one county in Mississippi. |
|||||
| Ransomware | Dubai Municipality (UAE) id12881 View details | United Arab Emirates | Public Sector | — | |
|
Dubai Municipality is a government body in Dubai, United Arab Emirates, serving the city through municipal administration and public services. Its website describes it as the home of the Government of Dubai and a municipal authority with jurisdiction over city services, while related pages note offerings such as service centers, veterinary clinics, abattoirs, and recycling centers. It also provides digital access through a mobile app for municipal services and city information. The entity was listed as a ransomware victim associated with daixin. |
|||||
| Ransomware | Dubai Municipality id22283 View details | United Arab Emirates | Public Sector | — | |
|
Dubai Municipality is the Government of Dubai municipal body with jurisdiction over city services and the upkeep of facilities in the Emirate of Dubai, United Arab Emirates and reports directly to the Dubai Executive Council. |
|||||
| Ransomware | Omni Hotels & Resorts (US) id11654 View details | United States | Hospitality / Food & Beverage / Tourism | — | |
|
Omni Hotels & Resorts is an American hotel company based in Dallas, Texas, operating more than 50 hotels and resorts across the United States and Canada. Its website promotes stays for vacation, wedding, and business travel, reflecting a hospitality portfolio that serves leisure and commercial guests. The brand spans hotels and resorts in the hospitality, food and beverage, and tourism sectors. It was listed as a ransomware victim associated with daixin. |
|||||
| Ransomware | Omni Hotels & Resorts id22282 View details | United States | Hospitality / Food & Beverage / Tourism | — | |
|
Omni Hotels & Resorts is an American privately held, international luxury hotel company based in Dallas, Texas. The company was founded in 1958 as Dunfey Hotels, and operates 50 properties in the United States, Canada, and formerly had a property in Mexico, totaling over 20,010 rooms and employing more than 23,000 people. |
|||||
| Ransomware | Graphic Solutions Group Inc (US) id9948 View details | Services | — | ||
|
gogsg.com is the web domain for GSG, also known as Graphic Solutions Group Inc., a U.S. wholesale distributor serving apparel decorating, digital print, electrical sign, and commercial markets. Company profiles indicate it operates in the Services sector and is based in Dallas, Texas. Its customer-facing site is used to present products, ordering, and company contact information. The domain was listed as a ransomware victim associated with daixin. |
|||||
| Ransomware | Graphic Solutions Group Inc id22281 View details | United States | Services | — | |
|
GSG digital printing technologies with a half a century of knowledge and experience in traditional sign, screen printing, embroidery and textile decorating. |
|||||
| Ransomware | North Texas Municipal Water District (US) id9731 View details | Public Sector | — | ||
|
North Texas Municipal Water District (NTMWD) is a Texas public sector utility based in Wylie, Texas, serving the North Texas region. It provides wholesale treated water, wastewater, and solid waste management services to more than 2 million people across a multi-city service area. NTMWD also operates major water infrastructure, including treatment plants, transmission pipelines, and pump stations, to support essential municipal services. The entity was listed as a ransomware victim associated with daixin. |
|||||
| Ransomware | North Texas Municipal Water District id22280 View details | United States | Public Sector | — | |
|
The North Texas Municipal Water District (NTMWD) provides vital wholesale water, wastewater and solid waste management services to more than two million people who call North Texas their home. |
|||||
| Ransomware | Bluewater Health (CA) and others id9338 View details | Canada | Healthcare / Pharma | — | |
|
Bluewater Health is a hospital in Sarnia, Ontario. The hospital now encompasses about 600,000 square feet (56,000 m2). It employs almost 1,800 staff and physicians, along with over 700 volunteers, and is Sarnia—Lambton's largest public sector employer. |
|||||
| Ransomware | Columbus Regional Healthcare System (US) id6798 View details | Healthcare / Pharma | — | ||
|
crhealthcare.org is the website of Columbus Regional Healthcare System, a not-for-profit healthcare provider in Whiteville, North Carolina, serving patients through a licensed 154-bed system. Its services include a network of medical clinics offering primary care, urology, imaging, OB/GYN, and orthopedics, along with physician recruitment and other patient-facing information. The organization presents itself as a patient-first regional health system with accredited hospital services and specialty care. It was listed as a ransomware victim associated with daixin. |
|||||
| Ransomware | Columbus Regional Healthcare System id22279 View details | United States | Healthcare / Pharma | — | |
|
Columbus Regional Healthcare System has one of the highest volume and most experienced robotic surgical programs in Southeastern North Carolina. |
|||||
| Ransomware | Hit Promotional Products (US) id5969 View details | Communication / Marketing | — | ||
|
hitpromo.net is the website of Hit Promotional Products, a Largo, Florida-based company in the advertising and marketing services sector. It sells promotional products and branded merchandise, describing itself as a one-stop shop with more than 1,400 items and additional marketing services. The company has operated for decades and is headquartered at 7150 Bryan Dairy Road in Largo. It was listed as a ransomware victim associated with daixin. |
|||||
| Ransomware | Hit Promotional Products id22278 View details | United States | Communication / Marketing | — | |
|
Hit Promotional Products has been a leader in the promotional product industry. As a family-owned business with a long history, Hit Promotional want to build real relationships. |
|||||
| Ransomware | B&G Foods (CA, US) id5410 View details | United States | Agriculture / Food | — | |
|
bgfoods.com is the website of B&G Foods, Inc., a Parsippany, New Jersey–based American branded foods company. The company manufactures, sells, and distributes a portfolio of shelf-stable and frozen foods across the United States and Canada, including branded grocery products. Its brand portfolio spans a range of consumer food categories and reflects a multi-brand food manufacturing and distribution business. It was listed as a ransomware victim associated with daixin. |
|||||
| Ransomware | B&G Foods id22277 View details | United States | Agriculture / Food | — | |
|
B&G Foods, Inc. manufactures, sells, and distributes a portfolio of shelf-stable and frozen foods, and household products in the United States, Canada, and Puerto Rico. |
|||||
| Ransomware | Guardian Analytics (US) id5272 View details | Finance / Legal / Insurance | — | ||
|
guardiananalytics.com is associated with the finance, legal, and insurance sector and appears to operate as a business-focused analytics brand serving regulated industries in the United States. Publicly available search results do not provide a detailed company profile for this exact domain, so a precise description of offerings is not verifiable from the sources provided. In threat-intelligence indexing, it is safest to treat the entity as a sector-relevant organization tied to financial-services operations. It was listed as a ransomware victim associated with Daixin. |
|||||
| Ransomware | Guardian Analytics id22276 View details | Finance / Legal / Insurance | — | ||
|
Guardian Analytics is now a part of NICE Actimize, a business of NICE (Nasdaq:NICE). Consistently ranked as number one in the space, NICE Actimize is the largest and broadest provider of financial crime, risk and compliance solutions for regional and global financial institutions, as well as government regulators. With Guardian Analytics, financial institutions build trust, increase competitiveness, improve their customer experience, and scale operations. |
|||||
| Ransomware | Astra Daihatsu Motor (ID) id4647 View details | Indonesia | Manufacturing / Engineering | — | |
|
Astra Daihatsu Motor (ID) is Indonesia's largest car manufacturer by production output and installed capacity, operating in the Automobile Manufacturing industry within West Java and Jakarta. The company serves as the sole distributor and retailer of Daihatsu vehicles in Indonesia, offering a diverse range of family vehicles including the New Terios, All New Xenia, and New Rocky. It has been incorporated since 1978 and remains the second best-selling car brand behind Toyota in the country. Astra Daihatsu Motor (ID) was listed as a ransomware victim associated with the daixin threat actor. |
|||||
| Ransomware | Astra Daihatsu Motor id22275 View details | Indonesia | Manufacturing / Engineering | — | |
|
PT Astra Daihatsu Motor is an automobile manufacturing company based in Jakarta, Indonesia. It is a joint venture company between Daihatsu, Astra International and Toyota Tsusho. It is the largest car manufacturer in Indonesia by production output and installed capacity, and has been second best-selling car brand behind |
|||||
| Ransomware | AirAsia Group (MY, ID, TH) id4621 View details | Malaysia | Transportation / Travel / Logistics | — | |
|
AirAsia Group, now Capital A, is a Malaysian multinational holding company operating in Malaysia, Indonesia, and Thailand with a portfolio of synergistic travel and lifestyle businesses. It includes AirAsia, the largest low-cost airline in Malaysia by fleet size, offering scheduled domestic and international flights to over 166 destinations across 25 countries. The group provides enterprise travel solutions through its corporate booking platform with multi-user functionality for business clients. AirAsia Group was listed as a ransomware victim associated with the threat actor daixin. |
|||||
| Ransomware | AirAsia Group id22274 View details | Malaysia | Transportation / Travel / Logistics | — | |
|
AirAsia is a Malaysian multinational low-cost airline headquartered near Kuala Lumpur, Malaysia. It is the largest airline in Malaysia by fleet size and destinations. AirAsia operates scheduled domestic and international flights to more than 165 destinations. |
|||||
| Ransomware | OakBend Medical (USA) id4125 View details | United States | Healthcare / Pharma | — | |
|
medicine.oakbend refers to OakBend Medical Center, a nonprofit healthcare system serving Fort Bend County in the Greater Houston area of Texas, United States. It operates hospital campuses and outpatient locations in Richmond, Sugar Land, Houston, and Wharton, and offers services ranging from family practice and primary care to cardiology, orthopedics, geriatrics, surgery, and related specialty care. OakBend Medical Group describes itself as a multispecialty physician group supporting inpatient and outpatient needs across the region. It was listed as a ransomware victim associated with daixin. |
|||||
| Ransomware | OakBend Medical id22273 View details | United States | Healthcare / Pharma | — | |
|
OakBend Medical is passionately focused on patient-centered medicine.OakBend Medical Center: 450 Physicians on staff; 1,200 + Employees; 274 Beds ;50+ Locations; 8,500 Annual inpatients; 100,000 Annual outpatients; 40,000 Annual Emergency Room visits |
|||||
| Ransomware | OakBend Medical Center id4061 View details | United States | Healthcare / Pharma | — | |
|
No additional victim description available. |
|||||
| Ransomware | ISTA International GmbH id3938 View details | Energy | — | ||
|
ista International GmbH provides submetering and billing of water and energy consumption. The Company offers heat allocation, water, and communication meters, installation systems, and smoke detectors. ista International caters their services to property managers, homeowners, and energy utilities worldwide. (over 6,000 ista employees in 22 countries.) |
|||||
| Ransomware | Fitzgibbon Hospital (USA) id3901 View details | United States | Healthcare / Pharma | — | |
|
Fitzgibbon Hospital is a not-for-profit community hospital in Marshall, Missouri, serving central Missouri with essential health care services. Its offerings include acute care and a range of patient services such as women’s health, OBGYN, and family care. The hospital describes its mission as improving the health of the community through quality, compassionate care and personal attention. It was listed as a ransomware victim associated with daixin. |
|||||
| Ransomware | Fitzgibbon Hospital id22272 View details | United States | Healthcare / Pharma | — | |
|
Fitzgibbon Hospital is a leader in central Missouri in providing quality, compassionate care and personal attention to patients. |
|||||
| Ransomware | Trib Total Media (USA) id3900 View details | United States | Communication / Marketing | — | |
|
Trib Total Media is a Pennsylvania-based media company headquartered in Tarentum, serving Southwestern Pennsylvania. It delivers news, information, and advertising across multiple counties and provides newspapers, magazines, direct mail, e-newsletters, commercial printing, and digital services. The company also operates Tribune-Review and TribLIVE-branded publications and platforms for local audiences. Trib Total Media was listed as a ransomware victim associated with daixin. |
|||||
| Ransomware | Trib Total Media id22271 View details | Communication / Marketing | — | ||
|
Trib Total Media delivers news, information and advertising to portions of Allegheny, Westmoreland, Armstrong and Butler counties in Southwestern Pennsylvania. |
|||||