Skip to main content

Operator dossier

Donex is a ransomware operator no longer publishing new disclosures. Darkfield has indexed 5 public victims claimed by this operator between March 8, 2024. Donex is an emerging ransomware group first observed in March 2024 that appears to be financially motivated, having claimed five documented victims in its initial months of operation. The group's origin and affiliations remain unclear due to limited public documentation by major security researchers, though their targeting patterns suggest a relatively small-scale operation compared to established ransomware families. Donex has demonstrated a preference for targeting technology and transportation/logistics sectors, with documented attacks spanning multiple continents including victims in Italy, Czech Republic, United States, Netherlands, and Belgium, indicating either a broad opportunistic approach or the use of initial access brokers with diverse geographic reach. The group has also shown interest in agriculture and food production entities, though specific attack methodologies, encryption techniques, and extortion tactics have not been publicly documented by major threat intelligence firms. Given the group's recent emergence in early 2024 and limited public reporting, Donex appears to remain active but operates at a significantly smaller scale than major ransomware families, with insufficient public documentation to determine their current operational status or any law enforcement disruption efforts.

Most-targeted sectors

Most-affected countries

How we know this. Operator profiles on Darkfield are built from continuous monitoring of every leak site the group is known to operate, cross-correlated with community-curated feeds (RansomLook, ransomware.live, RansomWatch, MISP-galaxy). Status flips from active to inactive when no new disclosure appears for 60 days. MITRE ATT&CK mappings shown in the interactive section below are sourced from CISA, vendor analysis, and the MITRE community catalog — we attribute each technique back to its source. Aliases reflect operator re-brands and affiliate splits.

Inactive ransomware operator

All groups

Donex

5 victims indexed · first seen 2 years ago · last activity 2 years ago

5
Victims indexed
#256 of 369 tracked operators
<1m
Active period
Mar 2024 → Mar 2024
5
Countries hit
top Italy · 1

At a glance

Status
inactive
First seen
2 years ago
Last activity
2 years ago
Onion sites
1 known endpoint
Primary sector
Technology · 2 hits

About

Donex is an emerging ransomware group first observed in March 2024 that appears to be financially motivated, having claimed five documented victims in its initial months of operation. The group's origin and affiliations remain unclear due to limited public documentation by major security researchers, though their targeting patterns suggest a relatively small-scale operation compared to established ransomware families. Donex has demonstrated a preference for targeting technology and transportation/logistics sectors, with documented attacks spanning multiple continents including victims in Italy, Czech Republic, United States, Netherlands, and Belgium, indicating either a broad opportunistic approach or the use of initial access brokers with diverse geographic reach. The group has also shown interest in agriculture and food production entities, though specific attack methodologies, encryption techniques, and extortion tactics have not been publicly documented by major threat intelligence firms. Given the group's recent emergence in early 2024 and limited public reporting, Donex appears to remain active but operates at a significantly smaller scale than major ransomware families, with insufficient public documentation to determine their current operational status or any law enforcement disruption efforts.

References

5 links

External sources curated by the MISP threat-intel community.

Timeline

1 months
2024-03-01T00:00:00+00:00 · 5
2024-03-01T00:00:00+00:002024-03-01T00:00:00+00:00

Top countries

🇮🇹 Italy
1
🇨🇿 Czech Republic
1
🇺🇸 United States
1
🇳🇱 Netherlands
1
🇧🇪 Belgium
1

Top sectors

Technology
2
Transportation/Logistics
1
Agriculture and Food Production
1

MITRE ATT&CK

4 techniques · 3 tactics

Tactics

Initial AccessExecutionImpact

Techniques

  • T1566Phishing
  • T1190Exploit Public-Facing Application
  • T1204User Execution
  • T1486Data Encrypted for Impact

Recent victims

Loading…

Onion infrastructure

1 known
  • http://g3h3klsev3eiofxhykmtenmdpi67wzmaixredk5pjuttbx7okcfkftqd.onion

Source

Updated 2 years ago

Data on this page is sourced from the group's own leak posts, cross-checked with public ransomware trackers (RansomLook, ransomware.live, RansomWatch), MITRE ATT&CK, and our own Tor and Telegram crawlers. This is a public observatory page — share freely.

Get alerted the next time Donex posts a victim.

Add Donex to your watchlist — Pro pings you within 5 minutes of any new Donex leak-site post, Telegram callout, or affiliate-rebrand inference.