d0glun
- First seen
- 2025-01-15 00:00:00
- Malware type
- ransomware
- Last IoC activity
- 2026-05-24 02:57:21
- Profile updated
- 2026-07-07 13:55:14
Targeted industries: professional-services technology-and-telecommunications
Context
D0glun is a crypto-ransomware strain first observed in January 2025, believed to be derived from Babuk via an intermediary variant known as Cheng Xilun. It uses AES-256 symmetric encryption and appends filenames with patterns such as .@D0glun@ or similar. The malware encrypts files rapidly, changes the desktop wallpaper, and drops ransom notes typically named @[email protected], Desktopcxl.txt, or help.exe. The campaign has shown signs of shared infrastructure and code reuse from Cheng Xilun, but there is no confirmed evidence of a large-scale or mature operation. Its activity so far suggests it is being tested or deployed by a small group or individual rather than a structured affiliate network.
Reports & references
- ransomlook.io — D0Glun (report)
- watchguard.com — D0Glun (report)
- pcrisk.com — 31986 D0Glun Ransomware (report)
- bazaar.abuse.ch — D0Glun (report)
- cs.beta.fletch.ai — D0Glun (report)