Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors donutleaks

Description

Donut Leaks (D0nut) is a data-extortion group active since August 2022 that developed its own ransomware encryptor, linked to attacks on Greece's DESFA gas company and Continental, believed to be an affiliate of multiple RaaS operations who pivoted to running an independent extortion platform. Known victims: 42

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

Donut Leaks (D0nut) is a medium-sophistication cybercrime group specializing in data extortion and ransomware campaigns. First identified in August 2022, they have targeted organizations across various sectors, including critical infrastructure and corporate entities. Their primary motivation is financial gain, achieved through ransomware deployment and data exfiltration.

Goals & Targeting

Donut Leaks' strategic objectives revolve around generating financial profit through high-impact ransomware deployments and data extortions. Their targeting profile suggests a focus on industries that would pay significant ransoms to avoid operational disruption, such as energy and automotive sectors. Victims include critical infrastructure companies and large corporations with whom downtime could lead to severe consequences. This group appears motivated by financial gain over geopolitical or ideological goals.

Enhanced Description

Donut Leaks (D0nut) emerged as a significant threat in the cybercrime landscape beginning August 2022. The group operates with a clear focus on organizational-gain motives, leveraging sophisticated tactics to infiltrate victims and extort profits. Known for their self-developed ransomware encryptor, Donut Leaks has demonstrated both technical capability and operationalacity. Their victims include high-profile targets such as Greece's DESFA gas company and Continental, a automotive manufacturing concern. This suggests the group strategically selects targets with significant organizational value to maximize extortion payouts. The group is also suspected to be an affiliate of multiple Ransomware-as-a-Service (RaaS) operations before transitioning to running an independent extortion platform. Donut Leaks has not been tied to any specific regional or sectoralpreferences, but their campaigns have predominantly affected European entities thus far.

Key Capabilities

  • Ransomware development and deployment
  • Data exfiltration techniques
  • Phishing campaigns using Office documents
  • Command and control communication mechanisms
  • Independent extortion platform operation

MITRE ATT&CK Tactics

Credential Access
Exfiltration
Defense Evasion
Discovery
Lateral Movement
Collection

Software / Tooling

Custom ransomware encryptor
Phishing email templates
C2 communications tools
File compression tools for exfiltration

Campaigns & Victims

Donut Leaks has been observed conducting campaigns targeting European organizations, particularly in the energy and automotive sectors. They are known to utilize spear-phishing emails as initial infection vectors. Their campaigns often involve high-volume data exfiltration prior to deploying ransomware on victim networks. Notable campaigns include attacks against DESFA and Continental, which suggest a preference for high-paying targets in critical infrastructure industries.

IOC Patterns

  • Phishing emails with embedded Office documents
  • Ransomware notes left within infected systems
  • Network communication attempts to known D0nut platforms
  • Exfiltration of data using加密 archives sent to external servers

Recommended Actions

  • Enhance email filtering and phishing detection mechanisms
  • Monitor for异常网络活动and unusual file hashes associated with Donut Leaks campaigns
  • Implement strong credentialsecurity measures, such as multi-factor authentication
  • Conduct regular backup exercises and ensure backups are isolated from network access
  • Educate employees about phishing tactics through continuous training programs
  • Adopt endpoint detection and response (EDR) solutions to identify known Donut Leaks TTPs
  • Establish a dedicated incident response team to handle ransomware incidents promptly

Suggested Tags

APT
ransomware
financial-gain
espionage
extortion
energy-sector
automotive-sector

Confidence Assessment

Confidence in Donut Leaks' described activities and modus operandi is high, based on observed campaign patterns and victimology. However, further analysis of their technical tools and detailed attack vectors would improve understanding of this group's specific capabilities. The absence of specific sectoral or geographic targeting suggests a broad-based threat that requires vigilance across industries.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
APT
ransomware
financial-gain
espionage
extortion
energy-sector
automotive-sector

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Aug 24, 2022
Last Seen
Jul 24, 2024
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.