Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Description

DoNex is a ransomware strain that emerged in March 2024 as the latest rebrand of a lineage beginning with Muse (2022) → DarkRace (2023) → DoNex, targeting enterprises in the US and Europe using double-extortion; Avast released a free decryptor in July 2024 after discovering a cryptographic flaw. Known victims: 5

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

DoNex is a ransomware strain that emerged in March 2024 as part of an evolving lineage, targeting enterprises in the US and Europe. The group employs double-extortion tactics, encrypting data and threatening to leak stolen information unless a ransom is paid. A free decryptor was released by Avast in July 2024 after discovering a cryptographic flaw in the ransomware.

Goals & Targeting

DoNex appears to target enterprises across multiple sectors in the US and Europe, focusing on maximizing financial gain through ransom payments. The choice of double extortion indicates a strategic focus on pressuring victims to comply with demands. The group's targeting profile suggests an emphasis on high-value organizations that are likely to have significant data assets and potentially fewer defenses against sophisticated attacks.

Enhanced Description

DoNex represents the latest iteration of a ransomware lineage that began with the Muse strain in 2022, followed by DarkRace in 2023, and culminating in DoNex. The group primarily targets enterprises in the United States and Europe, leveraging double-extortion techniques to maximize financial gain. Victims are subjected to data encryption, followed by demands for payment in exchange for decryption keys. If the ransom is not paid, the attackers threaten to publish stolen data online. The emergence of a decryptor tool by Avast highlights vulnerabilities in the ransomware's cryptographic implementation. This suggests that while the group has achieved some level of technical proficiency, there are potential weaknesses that can be exploited.

Key Capabilities

  • Ransomware deployment
  • Double-extortion tactics
  • Network infiltration techniques
  • Social engineering for initial access

Software / Tooling

Double extortion ransomware
Spear-phishing tools

Campaigns & Victims

DoNex campaigns have been observed targeting mid-sized to large enterprises, leveraging phishing and network infiltration techniques. The group's operational timeline is limited to less than a month as of July 2024, with only five known victims identified. Notable operations include the successful deployment of the ransomware in multiple industries and the subsequent decryption capability made available by Avast.

IOC Patterns

  • Spear-phishing emails targeting enterprise employees
  • Encrypted files with specific extensions
  • Network traffic spikes indicating lateral movement

Recommended Actions

  • Implement robust email filtering to detect phishing attempts
  • Patch systems and software to address potential vulnerabilities
  • Monitor network activity for signs of unauthorized access
  • Establish incident response plans to handle ransomware incidents
  • Encrypt sensitive data to mitigate the impact of ransomware attacks

Suggested Tags

Ransomware
Organized Crime
Double Extortion
Financial Gain

Confidence Assessment

Moderate confidence in the details provided, with some gaps in understanding the group's specific TTPs and tools. The emergence of a decryptor suggests that the ransomware may have limited sophistication relative to more established groups. Additional intelligence on their exact methodologies and tools would enhance understanding.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

16

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Organized Crime
Double Extortion
Financial Gain

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Feb 22, 2024
Last Seen
Feb 27, 2024
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.