dan0n
- First seen
- 2024-04-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Profile updated
- 2026-07-07 13:51:26
Targeted industries: professional-services technology-and-telecommunications healthcare-and-pharmaceutical transportation-and-logistics
Targeted regions: country_code:us country_code:ie country_code:kr
Context
dAn0n is a data-extortion actor that first appeared in April 2024. Operating primarily in a leak-focused extortion model, they publish stolen data on a Tor-hosted site rather than encrypting files. Their victims include organizations across sectors like business services, technology, healthcare, transportation, and legal—all largely based in the United States, with a few in Ireland and South Korea. Activity surged in May 2024, landing them in the top 10 most active ransomware actors that month. Despite limited branding efforts, their smaller operational footprint has allowed for swift, targeted breaches that prioritize rapid data exposure over elaborate cryptographic tactics.
Reports & references
- ransomlook.io — Dan0N (report)
- watchguard.com — Dan0N (report)
- sos-vo.org — Cybersecurity Snapshots Dan0N And Arcus Media Ransomware Groups (report)
- nccgroup.com — Ncc Group Monthly Threat Pulse Review Of May 2024 (report)