Ransomware Group intelligence
Donex
InactiveTrack Donex with 5 published victims and 1 known leak locations in a single intelligence view.
Overview
Donex is tracked by Breach House as a ransomware group with 5 published victims.
Belgium is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Down checked 5h ago | g3h3klsev3eiofxhykmtenmdpi67wzmaixredk5pjuttbx7okcfkftqd.onion |
Top Activity Sectors (3)
Typical Attacks (8)
▼MITRE ATT&CK does not currently catalogue Donex, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: donex uses PowerShell scripts to execute malicious commands and deploy ransomware payloads across compromised systems.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: donex modifies Windows Registry Run Keys to ensure malware persistence across reboots on infected endpoints.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: donex disables security tools like antivirus software to evade detection and ensure ransomware execution proceeds unimpeded.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1027.016 Junk Code Insertion Stealth
What they do: donex inserts junk code into binaries to evade static analysis and detection by security monitoring tools.
What that means: Adversaries may use junk code / dead code to obfuscate a malware’s functionality.
-
T1070.004 File Deletion Stealth
What they do: donex deletes Volume Shadow Copies and backup files via command-line tools to prevent data recovery without paying the ransom.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1135 Network Share Discovery Discovery
What they do: donex performs network share discovery to identify accessible remote directories for lateral movement and data targeting.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1560.001 Archive via Utility Collection
What they do: donex archives stolen victim data using utility tools prior to exfiltration to support extortion demands.
What that means: Adversaries may use utilities to compress and/or encrypt collected data prior to exfiltration.
-
T1486 Data Encrypted for Impact Impact
What they do: donex encrypts victim files using strong symmetric encryption, rendering business data inaccessible until payment is demanded.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
Victims (5)
Search, filter and paginate the victim timeline for Donex. Showing 1–5 of 5.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | vdhelm id11138 View details | Netherlands | Transportation / Travel / Logistics | ||
|
Van der Helm is a 4PL logistic service provider with a limitless passion for transport and logistics. From our offices in Den Hoor ... |
|||||
| Ransomware | PFLEET id11137 View details | United States | Services | ||
|
P-Fleet is a leader in expense and payment management solutions for commercial fleets, including those with owner-operators and in ... |
|||||
| Ransomware | elsapspa id11136 View details | Italy | Communication / Marketing | ||
|
Da oltre 50 anni, Elsap è un’impresa dedita alla rappresentanza e alla distribuzione di componenti elettronici ed elettromeccanici ... |
|||||
| Ransomware | CHOCOTOPIA id11135 View details | Czechia | Communication / Marketing | ||
|
Chocotopia is a center of entertainment in the heart of Prague. You can visit here Museum of Chocolate and experience Chocolate ... |
|||||
| Ransomware | mirel id11134 View details | Belgium | Communication / Marketing | ||
|
Nous sommes votre partenaire en matière de recrutement et de sélection. Nous nous déplaçons sans engagement en entreprise afin de ... |
|||||