Uptime Hamster: 10d 18h 21mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza dAn0n

dAn0n

1 incidentes 0 paises 0 sectores ransomware Ultimo: 2026-06-29
Ver en IntelTracker → APTTrail →
dAn0n is a financially motivated cyber extortion group that first emerged in the spring of 2024, distinguishing itself by initially operating as a data broker rather than deploying traditional ransomware encryption. The group specialized in exfiltrating sensitive data and subsequently using aggressive public pressure tactics to coerce victims into paying ransoms for the data's return and to prevent its public release. This unique approach involved a detailed, multi-step extortion process tracked via a graphical user interface on their data leak site, informing various stakeholders such as leadership, insurance companies, clients, and regulatory authorities. Although their operations under the dAn0n name ceased in late August 2024 after publishing 19 victims, the group reportedly reappeared in 2025 as 'White Lock', which transitioned to utilizing traditional crypto-ransomware.

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / leak siteunknownransomware.anggipradana.comRansomware Group: dAn0n
Tecnicas MITRE
T1566.001, T1078, T1059.001, T1490, T1486
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises objetivo (SOCRadar)

HungaryIrelandKorea, Republic ofNew CaledoniaUnited States

Sectores objetivo (SOCRadar)

Construction of BuildingsOther Information ServicesSoftware PublishersReal EstateHospitalsEnterprises & HoldingAccommodationManufacturingConstructionElectrical Equipment, Appliance, and Component Manufacturing

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com