Ransomware Group intelligence
Dunghill
InactiveTrack Dunghill with 16 published victims and 2 known leak locations in a single intelligence view.
Overview
Dunghill is tracked by Breach House as a ransomware group with 16 published victims.
United Kingdom is currently the most targeted country in this dataset.
2 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (2)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Down checked 1h ago | p66slxmtum2ox4jpayco6ai3qfehd5urgrs4oximjzklxcol264driqd.onion |
| Leak location 2 | Onion service | Down checked 1h ago | nsalewdnfclsowcal6kn5csm4ryqmfpijznxwictukhrgvz2vbmjjjyd.onion |
Top Activity Sectors (8)
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Dunghill, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: dunghill executes malicious commands via PowerShell scripts to stage payloads and manipulate system processes.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1106 Native API Execution
What they do: dunghill leverages native API calls to bypass detection while executing core ransomware functions.
What that means: Adversaries may interact with the native OS application programming interface (API) to execute behaviors.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: dunghill disables antivirus tools and modifies security software configurations to evade detection.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: dunghill deletes Volume Shadow Copies and backup directories via system commands to prevent recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1110 Brute Force Credential Access
What they do: dunghill brute-forces local accounts using credential lists to gain initial access to victim networks.
What that means: Adversaries may use brute force techniques to gain access to accounts when passwords are unknown or when password hashes are obtained.
-
T1057 Process Discovery Discovery
What they do: dunghill discovers running processes using process enumeration tools to identify critical services for disruption.
What that means: Adversaries may attempt to get information about running processes on a system.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: dunghill spreads laterally through SMB/Windows Admin Shares to encrypt additional networked systems.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: dunghill encrypts victim files using custom ransomware binaries targeting communication and marketing data.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1489 Service Stop Impact
What they do: dunghill terminates critical Windows services via kill commands to disrupt operational continuity.
What that means: Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
-
T1490 Inhibit System Recovery Impact
What they do: dunghill executes service stop commands to disable backup systems and isolate compromised infrastructure.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Victims (16)
Search, filter and paginate the victim timeline for Dunghill. Showing 1–16 of 16.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | The Printing House id20914 View details | Canada | Communication / Marketing | ||
|
No additional victim description available. |
|||||
| Ransomware | Linney id19583 View details | United Kingdom | Communication / Marketing | ||
|
Linney is a sixth generation, world-class, multichannel marketing services group. It offers graphic design, brand strategy, copywriting, social media campaigns, website design and build, data analysis, content scheduling, prototyping, eCommerce integrations, film editing and video production, reporting and analytics, and other solutions. For more than a decade, Linney has produced and managed marketing campaigns within McDonald's restaurants. The company is currently preparing a marketing campaign for Starbucks in the spring of 2025. |
|||||
| Ransomware | Nuevatel id13368 View details | Bolivia, Plurinational State of | Telecommunications | ||
|
Nuevatel PCS de Bolivia S.A., better known as VIVA, is a Bolivian wireless network operator and telecommunications company. It was founded in 1999. It is currently among the largest companies in the country. Viva is the third-largest wireless carrier in Bolivia, with a market share of 12.9% |
|||||
| Ransomware | Nexperia id11596 View details | United States | Manufacturing / Engineering | ||
|
Headquartered in the Netherlands, Nexperia is a global semiconductor company with a rich European history and more than 15,000 employees in Europe, Asia and the United States. As a leading expert in the design and manufacture of mission-critical semiconductors, Nexperia components provide the basic functionality for virtually every electronic device in the world - from automotive and industrial to mobile and consumer applications. |
|||||
| Ransomware | Array Networks id11033 View details | Taiwan, Province of China | Telecommunications | ||
|
Array Networks is an American networking hardware company. It sells network traffic encryption tools. Was founded in 2000 by Lawrence Lu and is based in Milpitas, California. It received funding from the venture capital firm U.S. Venture Partners and the private equity firm H&Q Asia Pacific. On May 13, 2009, Array Networks became the first non-Taiwan company to be listed on the Taiwan Stock Exchange. The company sold 54 million shares that had a total value of about $79 million. In 2009, 43% of the company's market share was in China, and its main product type sold there consisted of SSL VPN devices. |
|||||
| Ransomware | Supply Technology id9855 View details | IT | |||
|
Supply Technologies, a subsidiary of ParkOhio(NASDAQ:PKOH), specializes in supplier selection and management, planning, implementing, managing the physical flow of product for world-class international manufacturing companies, and servicing customers in the various markets. Supply Technologies has expertise in global sourcing with more than 7,500 suppliers worldwide and ensures that you’ll get the exact parts you need, on time, at the best quality and at the right price. |
|||||
| Ransomware | Robins & Morton id8868 View details | Healthcare / Pharma | |||
|
Robins and Morton is a company operating as a construction firm. It specializes in planning and design, construction management, multiple delivery methods, self-performed work, and green building. The company serves healthcare, government, and commercial markets. In the past ten years alone, it have completed nearly $10 billion in projects. These projects vary from major new hospitals and complex renovations, to hospitality projects and a variety of other commercial work. |
|||||
| Ransomware | CannonDesign id8867 View details | Construction / Real Estate | |||
|
CannonDesign is a global architecture, engineering and consulting practice that provides services for a range of project types, including hospitals and medical centers, corporate headquarters and commercial office buildings, higher education and PK-12 education facilities, hotels and hospitality, mixed-use, sports facilities, and science and research buildings. In 2017 and 2019, Fast Company named CannonDesign one of the 10 most innovative architecture firms in the world. |
|||||
| Ransomware | Roper & Vertafore id8865 View details | Finance / Legal / Insurance | |||
|
Vertafore is a Denver-based insurance technology company. It has developed various software for insurance companies, such as content management and workflow software, insurance knowledge base, data and analytics. It's insurance management software solutions allow participants in the insurance distribution channel to adapt to an evolving insurance industry by efficiently scaling their businesses through deeper access to information and insights. |
|||||
| Ransomware | Go-Ahead Group id8864 View details | United Kingdom | Transportation / Travel / Logistics | ||
|
Go-Ahead Group plc is a passenger transport company based in Newcastle upon Tyne, England. The majority of its operations are within the United Kingdom, Ireland, Singapore, Norway, and Germany. Go-Ahead diversified into ground handling services at various British airports via the acquisition of Gatwick Handling International, British Midland, and Reed Aviation. Acquired numerous other British transport companies, including Thames Travel, Carousel Buses, Hedingham, Anglian Bus, and HC Chambers & Son. It was contracted to operate bus and rail services in Germany and Singapore. During January 2023, it was announced that Go-Ahead was expanding into the Australian market via the U-Go Mobility joint venture with the engineering company UFL. |
|||||
| Ransomware | Ropertech.com & Vertafore.com id8862 View details | IT | |||
|
Vertafore is a Denver-based insurance technology company. It has developed various software for insurance companies, such as content management and workflow software, insurance knowledge base, data and analytics. It's insurance management software solutions allow participants in the insurance distribution channel to adapt to an evolving insurance industry by efficiently scaling their businesses through deeper access to information and insights. |
|||||
| Ransomware | Sabre Corporation id8513 View details | Transportation / Travel / Logistics | |||
|
Sabre Corporation is the largest global distribution systems provider for air bookings in North America. It's software, data, mobile and distribution solutions are used by hundreds of airlines and thousands of hotel properties to manage critical operations. Sabre is a leading software and technology company that powers the global travel industry. It partners with airlines, hoteliers, agencies and other travel partners to retail, distribute and fulfill travel. Its technology is the intelligence behind mobile apps, airport check-in kiosks, online travel sites, airline and hotel reservation networks, travel agent terminals, and scores of other travel solutions. |
|||||
| Ransomware | Sysco Corporation id6661 View details | Communication / Marketing | |||
|
Sysco Corporation is an American multinational corporation involved in marketing and distributing food products, smallwares, kitchen equipment and tabletop items to restaurants, healthcare and educational facilities, hospitality businesses like hotels and inns, and wholesale to other companies that provide foodservice. Sysco is the world's largest broadline food distributor; it has more than 600,000 clients in a wide array of fields. Management consulting is also an integral part of their services. The company operates approximately 330 distribution facilities worldwide; providing service to over 90 countries. |
|||||
| Ransomware | Gentex Corporation id6660 View details | Communication / Marketing | |||
|
Gentex Corporation is an American electronics and technology company that develops, designs and manufactures automatic-dimming rear-view mirrors, camera-based driver assistance systems, and other equipment for the global automotive industry. They produce dimmable aircraft windows for the commercial, business and general aviation markets. In addition, the company produces photoelectric smoke detectors, signaling devices, and the HomeLink Wireless Control System for the North American fire protection market. The company's customers are GM, Ford, BMW, Mercedes, Tesla, Airbus, Audi, Toyota, Mazda, Nissan, Honda, Porshe, Bentley and so on. |
|||||
| Ransomware | ANDRADE GUTIERREZ & ZAGOPE id6659 View details | Brazil | Manufacturing / Engineering | ||
|
ANDRADE GUTIERREZ is a Brazilian private multinational conglomerate headquartered in Belo Horizonte. As of 2013, Andrade Gutierrez is the second largest construction company in Brazil with branches in 44 countries and a net income of 8 billion BRL. In the engineering segment, AG operates in the construction of hydroelectric power plants, thermoelectric power plants, nuclear power plants, petrochemical plants, mining, steel industry, refineries, harbors, subways, sanitation and urbanization, airports, railroads, civil engineering. |
|||||
| Ransomware | Incredible Technologies id6079 View details | IT | |||
|
Incredible Technologies is an American developer and manufacturer of coin-operated video games and Class III casino games based in Vernon Hills, Illinois. The company's most common product is the Golden Tee Golf series. IT, Inc. products and gaming software are used in more than 50 counties around the world. |
|||||