dAn0n emerged in early 2024 operating a RaaS model, rapidly claiming 13 victims in May 2024 alone, predominantly targeting US-based organizations in business services and filling the vacuum left by disruptions to LockBit and BlackCat/ALPHV. Known victims: 33
Objectives
Executive Summary
dan0n is a newly emerged threat actor operating a ransomware-as-a-service (RaaS) model, primarily targeting US-based organizations in the business services sector. They rapidly increased their activity in May 2024, filling a void left by interruptions to LockBit and BlackCat/ALPHV groups. Their operations are characterized by high-targeting approaches and significant financial gain motivations.
Goals & Targeting
dan0n's primary motivation appears to be financial gain through ransomware operations. Their targeting strategy focuses on sectors and geographies where they can achieve the highest yield with minimal risk. The focus on US-based business services suggests an understanding of market dynamics and potential victim value. dan0n likely targets organizations based on factors such as ease of access, perceived ability to pay ransoms, and limited defensive capabilities.
Enhanced Description
dan0n emerged on the cybercrime scene in early 2024, quickly establishing themselves as a competitor in the ransomware landscape. By leveraging a RaaS model, they were able to rapidly scale their operations, targeting mid-sized organizations primarily in the United States. Their emergence coincided with disruptions experienced by established groups like LockBit and BlackCat/ALPHV, allowing dan0n to fill a critical gap in the ransomware ecosystem. Initial evidence indicates that dan0n's campaigns are meticulously planned, focusing on maximizing financial gain through effective encryption and robust extortion tactics. The actor has demonstrated a preference for specific sectors, such as business services, which may be due to higher perceived profitability or lower defensive postures. Their rapid rise to prominence suggests they have either developed their own capabilities or collaborated with existing threat networks to achieve operational maturity. With 33 confirmed victims as of August 2024, dan0n has quickly established themselves as a significant player in the ransomware economy.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
dan0n's campaigns exhibit a high degree of operational efficiency and rapid victim engagement. Their targeting in May 2024, with 13 victims, indicates a well-coordinated campaign strategy. The actors have demonstrated adaptability by focusing on the business services sector, which may be less defended than other industries. Campaign patterns include pre-attack reconnaissance, rapid encryption of targeted systems, and follow-up extortion attempts through encrypted communication channels. Notable for their rapid rise to prominence without significant prior ties to known groups, dan0n appears to be a self-sufficient actor in the ransomware space. The group is expected to expand their operations globally, potentially targeting European and Asian markets as their confidence grows.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in dan0n's operational patterns and TTPs due to observable campaign activity and confirmed victims. However, limited visibility into their long-term goals and full capability set introduces some uncertainty. Additional research is needed on their toolset development and potential affiliations with other threat groups.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics