216.73.216.6

Helldown Ransomware: an overview of this emerging threat

· Published 20/11/2024 15:36 · Modified 21/11/2024 09:53

Export JSON

Essential information

Published
20/11/2024 15:36
Modified
21/11/2024 09:53
Tags
2024-11-20 CVE-2024-42057 data exfiltration double-extortion emerging threat helldown linux ransomware vmware esx windows zyxel vulnerability
Related entities
1 intrusion sets (apt), 18 techniques (mitre), 1 malware, 3 others

Description

is a new and highly active group that has claimed 31 victims in three months. It employs custom for and systems, engages in double extortion, and exploits vulnerabilities in Zyxel firewalls for initial access. The group exfiltrates large volumes of data, averaging 70GB per victim. Its shares similarities with Darkrace and Donex variants. The variant targets servers. While connections to other groups like Hellcat are unconfirmed, 's success seems to rely on exploiting undocumented vulnerabilities rather than sophisticated malware. The group's rapid evolution and targeting of virtualized infrastructures make it a significant .

External references