Also known as: tracked as, APT43, Bjorka, SkyWave, quic, Colddraw Ransomware, built a, OffSec, Lolkek, medium-sized, medium-sized bu, targeting nume, Dispossessor, active since August 2023, RA World, Raznatovic, Linux VMware, 54BB47h, Fonix, Gamaredon APT, Abyss Locker, ARCrypter, GlobeImposter, CosmicBeetle, PlayCrypt, N13V, operated by UNC2190, FonixCrypter
Doommageddon orchestrates attacks that blend ransomware delivery with a "data‑dump‑first" double extortion strategy. Their operations begin with carefully crafted spearphishing emails that deliver malicious Office templates or Outlook VBA attachments, enabling initial persistence via Run key registry entries and script execution. Once inside, the malware deploys obfuscated PowerShell, VBScript, and batch payloads; it then scans for Office documents on mapped drives and USB volumes and exfiltrates these files over HTTP/HTTPS channels controlled through fast‑flux DNS zones. The group’s toolkit includes self‑extracting archives (7z), hidden console utilities such as hidcon, and legitimate system binaries (rundll32, mshta.exe) used to mask malicious activity. It also leverages remote control via UltraVNC and creates scheduled tasks for persistence while taking frequent screenshots and deleting local copies of exfiltrated data to reduce forensic footprints. Doommageddon’s operations are coordinated through cloud or VPS infrastructure, sometimes employing geoblocking to limit payload downloads by region. The actor is known to use repetitive TLS certificates across its infrastructure, Base64‑encoded download scripts, and obfuscated driver files (.drv) to evade detection. Their campaign footprint includes numerous industries—financial services, healthcare, government, transportation, and critical infrastructure—demonstrating a broad targeting range with opportunistic selection of high-value victims.
Objectives
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Doommageddon is a medium‑sophistication ransomware group that uses double extortion tactics to target a wide array of sectors globally. Leveraging cloud hosting, fast‑flux DNS, and malicious Office macros, they execute sophisticated phishing campaigns, exfiltrate data quietly, and demand ransom for both encrypted files and leaked information.
Goals & Targeting
The group’s primary objective is financial gain via ransomware revenue augmented by a double‑extortion model that exploits both encrypted data and exfiltrated sensitive information. By targeting a wide spectrum of industries—including critical infrastructure, healthcare, finance, and government—Doommageddon seeks to maximize leverage over compromised organizations, increasing the likelihood of ransom payment. Their consistent use of geographically restricted payload delivery also hints at an awareness of regulatory environments and an intent to avoid overtly high‑risk regions.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Since its first observed activity in early March 2026, Doommageddon has executed a series of campaigns across more than thirty countries targeting critical sectors such as healthcare, finance, transportation, and energy. The actor frequently employs spearphishing with malicious Office templates to establish initial footholds, then expands lateral movement through file‑system scanning and data exfiltration over fast‑flux HTTP/HTTPS channels. Their notable operations—spanning from hospital attacks in the United States to manufacturing facilities in Turkey—reflect an opportunistic yet systematic approach that balances stealth (e.g., registry tampering, hidden execution) with aggressive extortion tactics. Operational tempo appears relatively steady, with incidents reported every few weeks, indicating sustained resource investment.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The available data provides a coherent view of Doommageddon’s threat profile, drawing from multiple independent indicators and known campaign patterns. While the synthesis resolves many overlaps, some ambiguities remain—particularly regarding precise attribution across all campaigns and the extent of the actor’s infrastructure. Additional evidence such as validated attribution artifacts or confirmed command‑and‑control domains would further solidify confidence.
No report generated yet.
No observed data linked yet.
52
Techniques
58
Tools
102
Campaigns
39
IOCs
0
Observed Data
13
Tactics