DoNex is a ransomware strain that emerged in March 2024 as the latest rebrand of a lineage beginning with Muse (2022) → DarkRace (2023) → DoNex, targeting enterprises in the US and Europe using double-extortion; Avast released a free decryptor in July 2024 after discovering a cryptographic flaw. Known victims: 5
Objectives
Executive Summary
DoNex is a ransomware strain that emerged in March 2024 as part of an evolving lineage, targeting enterprises in the US and Europe. The group employs double-extortion tactics, encrypting data and threatening to leak stolen information unless a ransom is paid. A free decryptor was released by Avast in July 2024 after discovering a cryptographic flaw in the ransomware.
Goals & Targeting
DoNex appears to target enterprises across multiple sectors in the US and Europe, focusing on maximizing financial gain through ransom payments. The choice of double extortion indicates a strategic focus on pressuring victims to comply with demands. The group's targeting profile suggests an emphasis on high-value organizations that are likely to have significant data assets and potentially fewer defenses against sophisticated attacks.
Enhanced Description
DoNex represents the latest iteration of a ransomware lineage that began with the Muse strain in 2022, followed by DarkRace in 2023, and culminating in DoNex. The group primarily targets enterprises in the United States and Europe, leveraging double-extortion techniques to maximize financial gain. Victims are subjected to data encryption, followed by demands for payment in exchange for decryption keys. If the ransom is not paid, the attackers threaten to publish stolen data online. The emergence of a decryptor tool by Avast highlights vulnerabilities in the ransomware's cryptographic implementation. This suggests that while the group has achieved some level of technical proficiency, there are potential weaknesses that can be exploited.
Key Capabilities
Software / Tooling
Campaigns & Victims
DoNex campaigns have been observed targeting mid-sized to large enterprises, leveraging phishing and network infiltration techniques. The group's operational timeline is limited to less than a month as of July 2024, with only five known victims identified. Notable operations include the successful deployment of the ransomware in multiple industries and the subsequent decryption capability made available by Avast.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate confidence in the details provided, with some gaps in understanding the group's specific TTPs and tools. The emergence of a decryptor suggests that the ransomware may have limited sophistication relative to more established groups. Additional intelligence on their exact methodologies and tools would enhance understanding.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
16
IOCs
0
Observed Data
0
Tactics