logo

Helldown ransomware exploits Zyxel VPN flaw to breach networks

ID: 2e9c3322-e4a0-5b71-b210-16a3a42c6b9c

STIX ID: report--2e9c3322-e4a0-5b71-b210-16a3a42c6b9c

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-11-19

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Helldown is an emerging ransomware operation reported by Sekoia that appears to exploit Zyxel firewall vulnerabilities (suspected CVE-2024-42057 and the later-tracked CVE-2024-11667) to establish VPN access (using accounts like 'OKSDW82A' and config 'zzz1.conf'), move laterally, exfiltrate large amounts of data and deploy Windows and Linux/MIPS encryptors; the group has listed multiple victims on an extortion site and published large data dumps, while some evidence suggests use of leaked builders and private n-day exploits.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.