donex
First seen March 8, 2024Active5 claimed victims
The claims below are reproduced as posted by donex on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.
Listed organisation? Contact [email protected].
Profile
DoNex is a ransomware strain that emerged in March 2024 as the latest rebrand of a lineage beginning with Muse (2022) → DarkRace (2023) → DoNex, targeting enterprises in the US and Europe using double-extortion; Avast released a free decryptor in July 2024 after discovering a cryptographic flaw.
Description from ransomware.live.
Claimed victims (as posted by the group — unverified)
| Victim (as posted) | Claimed on | Source | Press coverage |
|---|---|---|---|
| mirel | February 27, 2024 | ransomware_live | — |
| CHOCOTOPIA | February 27, 2024 | ransomware_live | — |
| elsapspa | February 24, 2024 | ransomware_live | — |
| PFLEET | February 23, 2024 | ransomware_live | — |
| vdhelm | February 22, 2024 | ransomware_live | — |
Claim data from ransomware.live and RansomLook (CC BY 4.0).