d0glun

First seen
2025-01-15 00:00:00
Malware type
ransomware
Last IoC activity
2026-05-24 02:57:21
Profile updated
2026-07-07 13:55:14

Targeted industries: professional-services technology-and-telecommunications

Context

D0glun is a crypto-ransomware strain first observed in January 2025, believed to be derived from Babuk via an intermediary variant known as Cheng Xilun. It uses AES-256 symmetric encryption and appends filenames with patterns such as .@D0glun@ or similar. The malware encrypts files rapidly, changes the desktop wallpaper, and drops ransom notes typically named @[email protected], Desktopcxl.txt, or help.exe. The campaign has shown signs of shared infrastructure and code reuse from Cheng Xilun, but there is no confirmed evidence of a large-scale or mature operation. Its activity so far suggests it is being tested or deployed by a small group or individual rather than a structured affiliate network.

Reports & references

  • ransomlook.io — D0Glun (report)
  • watchguard.com — D0Glun (report)
  • pcrisk.com — 31986 D0Glun Ransomware (report)
  • bazaar.abuse.ch — D0Glun (report)
  • cs.beta.fletch.ai — D0Glun (report)

External references