logo

dAn0n Hacker Group Reemerges as White Lock Ransomware

ID: 6b188752-ae51-5292-8be6-53c7d37e6cd4

STIX ID: report--6b188752-ae51-5292-8be6-53c7d37e6cd4

Feed Name: WatchGuard Secplicity Blog

Threat Score
70/100

Date Published: 2025-10-17

Date Updated: 2026-05-01

Author: Ryan Estes

...
...

White Lock is a newly observed ransomware operation tied to the dAn0n extortion group: four samples (earliest compile timestamp Sept 29, 2025) perform file encryption (appending '.fbin'), delete shadow copies, change the desktop wallpaper, and drop a 'c0ntact.txt' ransom note directing victims to a TOR chat (standard ransom appears to be 4 BTC). Investigators link White Lock and dAn0n by shared www subdomain hosting and email server subnet, and the report includes extensive IOCs (sample hashes, IPs, TOR and clearnet domains, ransom filenames) to support attribution and detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.