logo

Helldown Ransomware: an overview of this emerging threat

ID: 6836e0c0-2379-5e0e-8f2d-04748b299fbf

STIX ID: report--6836e0c0-2379-5e0e-8f2d-04748b299fbf

Feed Name: Sekoia.io Blog

Threat Score
75/100

Date Published: 2024-11-19

Date Updated: 2026-04-29

Author: Jeremy Scion and Sekoia TDR

...
...

Sekoia TDR reports on the Helldown intrusion set, an active ransomware operator responsible for at least 31 victims that exploits Zyxel firewall vulnerabilities to gain initial access, performs large-scale data exfiltration for double extortion, and deploys Windows and Linux ransomware (including ESX-targeting functionality). The analysis includes dynamic and static breakdowns of samples, IoCs (multiple SHA256 hashes and a Zyxel config artifact), observed TTPs (credential pivoting, shadow-copy deletion, process termination), and an assessment of possible ties to Darkrace/Donex rebrands though no definitive attribution is made.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.