Uptime Hamster: 11d 10h 15mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza mamona

mamona

2 incidentes 1 paises 0 sectores ransomware Ultimo: 2026-06-29
Aliases: Offline Ransomware
Ver en IntelTracker → APTTrail →
Mamona is a commodity ransomware strain that emerged in March 2025 with the public leak of its builder tool, subsequently becoming more widely adopted by cybercriminals. Initially used by affiliates of the BlackLock group, its operations were later taken over by the DragonForce group, which rebranded and enhanced activities under the Mamona banner following BlackLock's dismantling. This threat actor's primary motivation is financial, achieved through encrypting victim files and demanding ransom. Mamona distinguishes itself by operating entirely offline without relying on command-and-control infrastructure or data exfiltration, employing a unique timing mechanism that utilizes the Windows ping command to 127.0.0.7, and using a custom-built cryptographic algorithm for encryption instead of standard libraries. This builder-based model lowers the entry barrier, allowing less technical cybercriminals to launch attacks. While the ransomware's ransom note falsely claims data theft, analysis c

Aliases del actor

Offline Ransomware

Actores similares

Offline ransomwareransomware · 0lockbit3ransomware · 2016qilinransomware · 1933akiraransomware · 1524playransomware · 1268clopransomware · 1254lockbit2ransomware · 1002ransomhubransomware · 842incransomransomware · 832alphvransomware · 731

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / oniondownbdhjur3agrogoxvwobbzpptkxhyewnjrhzqj4ug2dyfhf3dopyvvurid.onionmamona
DLS / oniondownowt3kwkxod2pvxlv3uljzskfhebhrhoedrh5gqrxyyd6rrco4frzj5ad.onionmamona
DLS / leak sitedownransomware.anggipradana.comRansomware Group: mamona
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United States (1)

Paises objetivo (SOCRadar)

United Kingdom

Sectores objetivo (SOCRadar)

Wholesale TradeInformation ServicesEnterprises & HoldingHealthCare & Social AssistanceOtherPublic AdministrationNational Security&International AffairsSoftware PublishersBanking

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com