DoNex is a financially motivated ransomware operation that emerged publicly in March 2024, with its earliest known malware samples dating to February 2024. It has targeted victims in the United States and Europe. Its ransomware closely resembles Darkrace and exhibits code similarities to ransomware generated using the leaked LockBit builder; these similarities do not establish common operators or an affiliate relationship. DoNex uses Windows ransomware compiled with Microsoft Visual C/C++. It checks administrative group membership, prevents concurrent execution through a mutex, hides its console window, and prepares cryptographic context before encryption. It terminates antivirus, endpoint detection and response, and backup-related processes and stops services. The malware enumerates local drives and accessible network shares, encrypts files while excluding critical system files, and uses Windows Restart Manager to identify processes locking target files before terminating them. It deposits ransom notes, clears application, system, and security event logs, deletes its helper script, and forces a system restart after encryption. Avast has released a decryptor to help victims recover affected files.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
12 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only in a comparison of ransomware process-termination techniques.
DoNex is a financially motivated ransomware group active since early 2024, targeting US and European organizations. A decryptor is available for its victims.
Ransomware group using a LockBit-derived code base via similarities to Darkrace, conducting file encryption on local drives and accessible network shares, killing processes, stopping services, clearing event logs, and dropping ransom notes.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.