Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors dunghill

Also known as: darkangel

Description

Dunghill Leak is the data extortion site operated by the Dark Angels ransomware group, active since early 2023, targeting large enterprises across healthcare, finance, industrial, and technology sectors using a highly selective non-affiliate model, and responsible for a record-breaking $75 million ransom payment in 2024. Known victims: 16

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

Dunghill, also known as Dark Angel, is a medium-sophisticated criminal threat actor primarily motivated by organizational gain through ransomware activities and financial exploitation. Operating since April 2023, they have targeted large enterprises across healthcare, finance, industrial, and technology sectors with a highly selective non-affiliate model. Known for demanding significant ransoms, including a record-breaking $75 million in 2024, Dunghill poses a substantial threat to victimized organizations.

Goals & Targeting

Dunghill's strategic objectives center around maximizing financial gain through ransom payments and data extortion. They target large enterprises in sectors with high potential for financial loss and reputational damage, such as healthcare, finance, industrial, and technology. Their selection of victims suggests a focus on industries where downtime or data exposure could lead to significant financial penalties. The group's non-affiliate model indicates an operational preference to avoid associations that might increase their visibility, allowing them to maintain persistence and adaptability in their campaigns.

Enhanced Description

Dunghill is an active ransomware group operating under the Dark Angel moniker, launched in early 2023. They primarily target large enterprises across healthcare, finance, industrial, and technology sectors with a focus on data extortion and financial gain. Their unique non-affiliate operational model allows them to maintain a lower profile while maximizing their attack efficiency. Dunghill is known for leveraging sophisticated techniques to infiltrate victim networks, deploy ransomware, and exfiltrate sensitive data, which they threaten to leak unless a substantial ransom is paid. The group has demonstrated significant capabilities in compromising high-value targets, with notable success including the $75 million ransom payment in 2024. Their activities highlight an evolving ransomware landscape where attackers are increasingly focusing on specific sectors and employing targeted approaches to maximize their financial returns.

Key Capabilities

  • Advanced ransomware deployment
  • Data exfiltration and extortion tactics
  • Targeted attack planning
  • Sophisticated network infiltration techniques

MITRE ATT&CK Tactics

Initial Access (TA0046)
Lateral Movement (TA0054)
Exfiltration (TA0048)

ATT&CK Techniques

T1566.001
T1037
T1566.002
T1059.006

Software / Tooling

Custom ransomware
Data exfiltration tools

Campaigns & Victims

Dunghill's campaigns typically involve targeted attacks on high-value enterprises, leveraging sophisticated tactics to infiltrate networks and deploy ransomware. Their use of a non-affiliate model allows for a slower but more focused attack pattern, aiming for long-term financial gain rather than rapid deployment. Notable activity includes the $75 million ransom payment in 2024, highlighting their success in targeting financially significant organizations. Campaign patterns suggest a preference for quiet infiltration and persistent attacks to ensure maximum disruption before demanding ransoms.

IOC Patterns

  • Spear-phishing emails with malicious links or attachments
  • Network横向 movement indicators
  • Ransomware deployment markers

Recommended Actions

  • Implement robust network monitoring for anomalous activities
  • Regularly backup critical systems and test restoration processes
  • Educate employees on phishing and social engineering tactics
  • Enhance incident response plans to address ransomware scenarios

Suggested Tags

APT
ransomware
extortion
healthcare
finance

Confidence Assessment

Confidence in Dunghill's details is medium, with confirmed activities including the $75 million ransom payment and active use of their data extortion site. Limited technical indicators and attack telemetry are publicly available, preventing a more definitive assessment of their exact capabilities. Potential gaps include understanding their specific TTPs beyond general ransomware patterns and the full spectrum of targets and campaigns.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Healthcare Targeting
APT
ransomware
extortion
healthcare
finance

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Apr 10, 2023
Last Seen
Jul 1, 2025
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.