Helldown
Parsing : Enabled
Description
Helldown is an emerging ransomware group first identified in August 2024, known for its fast-evolving and cross-platform threat capabilities. It exploits critical vulnerabilities—most notably CVE-2024-42057 in Zyxel firewalls—for initial access and demonstrates modular design and anti-detection mechanisms. Helldown targets both Windows and Linux environments, including VMware and ESXi systems. It employs a double-extortion strategy: encrypting files with randomized extensions via executables like hellenc.exe, and threatening victims with data dump releases via its Tor-hosted leak site.
External Analysis |
https://www.truesec.com/hub/blog/helldown-ransomware-group |
https://blog.sekoia.io/helldown-ransomware-an-overview-of-this-emerging-threat |
https://hivepro.com/threat-advisory/new-helldown-ransomware-a-growing-threat-across-cross-platform-systems |
https://www.broadcom.com/support/security-center/protection-bulletin/helldown-ransomware |
Tox |
19A549A57160F384CF4E36EE1A24747ED99C623C48EA545F343296FB7092795D00875C94151E |
Urls |
Screen |
http://onyxcgfg4pjevvp5h34zvhaj45kbft3dg5r33j5vu3nyp7xic3vrzvad.onion/ |
Screen |
http://onyxcym4mjilrsptk5uo2dhesbwntuban55mvww2olk5ygqafhu3i3yd.onion |
Screen |
http://www.helldown.org |
Screen |
http://onyxcb44xvqra35m3lp3z26kf2pxrlbn64nbzvyvzjyc3uykzrwcjdid.onion |
|
Posts
Date |
Title |
Description |
Screen |
2024-11-06 |
klinkamkurpark |
klinik-am-kurpark.de |
Screen |
2024-11-06 |
hausdesstiftens.org |
hausdesstiftens.org |
Screen |
2024-11-06 |
nightnurse.ch |
www.nightnurse.ch |
Screen |
2024-11-06 |
fuelco |
fuelco-us.com |
Screen |
2024-11-06 |
VALLEYFIRM |
valleyfirm.com |
Screen |
2024-11-06 |
children |
generaldentistryforchildren.com |
Screen |
2024-11-06 |
knoxlawcenter |
www.knoxlawcenter.com |
Screen |
2024-11-06 |
AMERICANVENTURE |
americanventures.com |
Screen |
2024-11-06 |
CSIKBS |
www.csikitchenandbath.com |
Screen |
2024-11-06 |
SANJACINTOCOUNY |
www.co.san-jacinto.tx.us |
Screen |
2024-11-06 |
compassfs |
www.compassfs.net |
Screen |
2024-11-06 |
lacliniqueducoureur |
lacliniqueducoureur.com |
Screen |
2024-11-06 |
TIVOLI-33 |
tivoli-33.org |
Screen |
2024-11-06 |
qualiform.cz |
www.qualiform.cz |
Screen |
2024-11-06 |
SMARTS-ENGINEER |
www.smarts-engineering.de |
Screen |
2024-08-24 |
HBGJEWISHCOMMUN |
www.jewishharrisburg.org |
Screen |
2024-08-22 |
cincinnatipainphysicians |
www.cincinnatipainphysicians.com |
Screen |
2024-08-22 |
BARRYAVEPLATING |
Here's something encrypted, password is required to continue reading. |
Screen |
2024-08-22 |
RSK-IMMOBILIEN |
Here's something encrypted, password is required to continue reading. |
Screen |
2024-08-19 |
Khonaysser |
Here's something encrypted, password is required to continue reading. |
Screen |
2024-08-18 |
kbo |
Here's something encrypted, password is required to continue reading. |
Screen |
2024-08-17 |
zyxel |
Zyxel.eu |
Screen |
2024-08-14 |
hugwi |
hugwi.ch |
Screen |
2024-08-13 |
deganis |
deganis.fr |
Screen |
2024-08-13 |
SCHLATTNER |
SCHLATTNER.de |
Screen |
2024-08-13 |
XPERT |
XPERT Business Solutions GmbH |
Screen |
2024-08-13 |
MyFreightWorld |
MyFreightWorld |
Screen |
2024-08-13 |
cbmm |
cbmm.org |
Screen |
2024-08-13 |
ATP |
AZIENDA TRASPORTI PUBBLICI S.P.A. |
Screen |
2024-08-13 |
briju |
briju.pl |
Screen |
2024-08-13 |
vindix |
vindix.pl |
Screen |
2024-08-13 |
Albatros |
Albatros S.r.l. |
Screen |