Donut Leaks (D0nut) is a data-extortion group active since August 2022 that developed its own ransomware encryptor, linked to attacks on Greece's DESFA gas company and Continental, believed to be an affiliate of multiple RaaS operations who pivoted to running an independent extortion platform. Known victims: 42
Objectives
Executive Summary
Donut Leaks (D0nut) is a medium-sophistication cybercrime group specializing in data extortion and ransomware campaigns. First identified in August 2022, they have targeted organizations across various sectors, including critical infrastructure and corporate entities. Their primary motivation is financial gain, achieved through ransomware deployment and data exfiltration.
Goals & Targeting
Donut Leaks' strategic objectives revolve around generating financial profit through high-impact ransomware deployments and data extortions. Their targeting profile suggests a focus on industries that would pay significant ransoms to avoid operational disruption, such as energy and automotive sectors. Victims include critical infrastructure companies and large corporations with whom downtime could lead to severe consequences. This group appears motivated by financial gain over geopolitical or ideological goals.
Enhanced Description
Donut Leaks (D0nut) emerged as a significant threat in the cybercrime landscape beginning August 2022. The group operates with a clear focus on organizational-gain motives, leveraging sophisticated tactics to infiltrate victims and extort profits. Known for their self-developed ransomware encryptor, Donut Leaks has demonstrated both technical capability and operationalacity. Their victims include high-profile targets such as Greece's DESFA gas company and Continental, a automotive manufacturing concern. This suggests the group strategically selects targets with significant organizational value to maximize extortion payouts. The group is also suspected to be an affiliate of multiple Ransomware-as-a-Service (RaaS) operations before transitioning to running an independent extortion platform. Donut Leaks has not been tied to any specific regional or sectoralpreferences, but their campaigns have predominantly affected European entities thus far.
Key Capabilities
MITRE ATT&CK Tactics
Software / Tooling
Campaigns & Victims
Donut Leaks has been observed conducting campaigns targeting European organizations, particularly in the energy and automotive sectors. They are known to utilize spear-phishing emails as initial infection vectors. Their campaigns often involve high-volume data exfiltration prior to deploying ransomware on victim networks. Notable campaigns include attacks against DESFA and Continental, which suggest a preference for high-paying targets in critical infrastructure industries.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in Donut Leaks' described activities and modus operandi is high, based on observed campaign patterns and victimology. However, further analysis of their technical tools and detailed attack vectors would improve understanding of this group's specific capabilities. The absence of specific sectoral or geographic targeting suggests a broad-based threat that requires vigilance across industries.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics