Ransomware Group intelligence
Helldown
InactiveTrack Helldown with 37 published victims and 2 known leak locations in a single intelligence view.
Overview
Helldown is tracked by Breach House as a ransomware group with 37 published victims.
United States is currently the most targeted country in this dataset.
2 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (2)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 2 | Onion service | Down checked 2h ago | onyxcym4mjilrsptk5uo2dhesbwntuban55mvww2olk5ygqafhu3i3yd.onion |
| Leak location 1 | Onion service | Down checked 2h ago | onyxcgfg4pjevvp5h34zvhaj45kbft3dg5r33j5vu3nyp7xic3vrzvad.onion |
Top Activity Sectors (8)
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Helldown, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: helldown uses PowerShell scripts to execute malicious commands and spread payloads across compromised systems.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: helldown modifies registry run keys to establish persistence and ensure recurring execution after system reboots.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: helldown disables security tools like antivirus software to evade detection and ensure ransomware execution proceeds unimpeded.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: helldown deletes Volume Shadow Copies and backup directories via command-line tools to prevent data recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1003.001 LSASS Memory Credential Access
What they do: helldown dumps LSASS memory using credential-access tools to harvest user credentials for initial access or privilege escalation.
What that means: Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS).
-
T1135 Network Share Discovery Discovery
What they do: helldown performs network share discovery to identify accessible file shares for lateral movement and victim targeting.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: helldown exploits SMB/Windows Admin Shares for lateral movement between networked hosts within victim environments.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: helldown encrypts victim files using strong symmetric cryptography to hold data hostage for ransom demands.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1489 Service Stop Impact
What they do: helldown executes service stop commands to disable critical system services before encrypting files.
What that means: Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
-
T1490 Inhibit System Recovery Impact
What they do: helldown invokes system shutdown commands and service termination routines to disrupt recovery processes and maximize impact.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Tools Observed (5)
▼Software Helldown has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Credential theft
Defense evasion
Discovery & enumeration
LOLBAS (living-off-the-land binaries)
Remote monitoring & management
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Ransom Notes (1)
▼The note this group leaves on a compromised machine. Click a filename to read it.
Readme.[id].txt
--------------------------------------------------------------------------------------------
| |
| Hello dear Management of Active directory domain |
| |
| If you are reading this message,it means that: |
| |
| * your network infrastructure has been compromised |
| * critical data was leaked |
| * files are encrypted |
| * backups are deleted |
| |
| The best and only thing you can do is to cantact us |
| to setle the matter before any losses occurs |
| |
| All your critical data was leaked on our website |
| Download Tor browser:https://www.torproject.org |
| |
| http://onyxcym4mjilrsptk5uo2dhesbwntuban55mvww2olk5ygqafhu3i3yd.onion |
| |
| Download (https://qtox.github.io) to negotiate online |
| Tox ID:19A549A57160F384CF4E36EE1A24747ED99C623C48EA545F343296FB7092795D00875C94151E |
| |
| |
| [email protected] |
--------------------------------------------------------------------------------------------
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (37)
Search, filter and paginate the victim timeline for Helldown. Showing 1–37 of 37.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | klinkamkurpark id15199 View details | Germany | Other | ||
|
klinik-am-kurpark.de |
|||||
| Ransomware | hausdesstiftens.org id15198 View details | Germany | Other | ||
|
hausdesstiftens.org |
|||||
| Ransomware | nightnurse.ch id15197 View details | Switzerland | Other | ||
|
www.nightnurse.ch |
|||||
| Ransomware | fuelco id15196 View details | Energy | |||
|
fuelco-us.com |
|||||
| Ransomware | VALLEYFIRM id15195 View details | Hong Kong | Other | ||
|
valleyfirm.com |
|||||
| Ransomware | children id15194 View details | India | Other | ||
|
generaldentistryforchildren.com |
|||||
| Ransomware | knoxlawcenter id15193 View details | United States | Finance / Legal / Insurance | ||
|
www.knoxlawcenter.com |
|||||
| Ransomware | AMERICANVENTURE id15192 View details | United States | Other | ||
|
americanventures.com |
|||||
| Ransomware | CSIKBS id15191 View details | Japan | Other | ||
|
www.csikitchenandbath.com |
|||||
| Ransomware | SANJACINTOCOUNY id15190 View details | United States | Other | ||
|
www.co.san-jacinto.tx.us |
|||||
| Ransomware | compassfs id15189 View details | United States | Other | ||
|
www.compassfs.net |
|||||
| Ransomware | lacliniqueducoureur id15188 View details | Canada | Other | ||
|
lacliniqueducoureur.com |
|||||
| Ransomware | TIVOLI-33 id15187 View details | France | Other | ||
|
tivoli-33.org |
|||||
| Ransomware | qualiform.cz id15186 View details | Czechia | Other | ||
|
www.qualiform.cz |
|||||
| Ransomware | SMARTS-ENGINEER id15185 View details | Russian Federation | Manufacturing / Engineering | ||
|
www.smarts-engineering.de |
|||||
| Ransomware | HBGJEWISHCOMMUN id13970 View details | United States | Other | ||
|
www.jewishharrisburg.org |
|||||
| Ransomware | barryavenueplating id13962 View details | United States | Hospitality / Food & Beverage / Tourism | ||
|
www.barryavenueplating.com |
|||||
| Ransomware | rsk-immobilien id13961 View details | Germany | Other | ||
|
RSK Immobilien GmbH is a real estate company based in Weißenfels, Saxony-Anhalt, Germany. Its stated core areas are project development, implementation, and marketing of high-quality single-family and multi-family homes, with contact details and office information published on its official site. Public business directories also describe a related RSK Immobilien Bauträger GmbH & Co. KG in the buying and selling of own real estate sector, headquartered in Weißenfels. The entity was listed as a ransomware victim associated with Helldown. |
|||||
| Ransomware | cincinnatipainphysicians id13949 View details | United States | Services | ||
|
www.cincinnatipainphysicians.com |
|||||
| Ransomware | kbosecurity.co.uk id13936 View details | United Kingdom | Other | ||
|
kbosecurity.co.uk |
|||||
| Ransomware | khonaysser.com id13935 View details | Lebanon | Other | ||
|
khonaysser.com |
|||||
| Ransomware | BARRYAVEPLATING id13922 View details | United States | Hospitality / Food & Beverage / Tourism | ||
|
BARRYAVEPLATING |
|||||
| Ransomware | RSK-IMMOBILIEN id13921 View details | Germany | Other | ||
|
RSK-IMMOBILIEN |
|||||
| Ransomware | ATP id13905 View details | Italy | Other | ||
|
atpsassari.it |
|||||
| Ransomware | Khonaysser id13896 View details | Lebanon | Other | ||
|
Khonaysser |
|||||
| Ransomware | kbo id13890 View details | United Kingdom | Other | ||
|
Here's something encrypted, password is required to continue reading. |
|||||
| Ransomware | zyxel id13867 View details | Netherlands | IT | ||
|
Zyxel.eu is a European branch of Zyxel Communications Corporation, a global leader in networking solutions. It specializes in providing innovative and reliable internet connectivity products and services, including routers, switches, security appliances, and cloud-based network management systems. Zyxel focuses on empowering businesses and home users with cutting-edge technology to enhance their digital experiences. |
|||||
| Ransomware | hugwi id13824 View details | Switzerland | IT | ||
|
Hugwi.ch is a Swiss-based company specializing in providing cutting-edge digital solutions, with a focus on web development, e-commerce, and custom software. They offer tailored services to businesses, enhancing their online presence and operational efficiency. Known for their innovation and customer-centric approach, Hugwi.ch combines technical expertise with creative design to deliver high-quality, scalable solutions that meet diverse client needs. |
|||||
| Ransomware | SCHLATTNER id13810 View details | Germany | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | deganis id13809 View details | France | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | XPERT Business Solutions GmbH id13802 View details | Austria | Services | ||
|
No additional victim description available. |
|||||
| Ransomware | MyFreightWorld id13801 View details | United States | Transportation / Travel / Logistics | ||
|
No additional victim description available. |
|||||
| Ransomware | cbmm id13800 View details | Brazil | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | AZIENDA TRASPORTI PUBBLICI S.P.A. id13799 View details | Italy | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | briju id13798 View details | Poland | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | vindix id13797 View details | Poland | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | Albatros id13796 View details | Italy | Other | ||
|
No additional victim description available. |
|||||