donex
- First seen
- 2024-03-15 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Profile updated
- 2026-07-07 13:51:12
Targeted industries: financial-services healthcare-and-pharmaceutical government-and-public-sector
Context
The ransomware group known as DoNex was first identified in mid-March 2024. According to the data collected, the samples used by the group were compiled in mid-February, suggesting that it is a relatively new operation.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Donex_Auto (yara-rule)
Related threat objects
- darkrace (malware)
Reports & references
- helpnetsecurity.com — Decryptor Donex Muse Darkrace Fake Lockbit 3 0 (report)
- ransomlook.io — Donex (report)
- fortinet.com — Ransomware Roundup Keganohitobito And Donex (report)
- Trend Micro — New Donex Ransomware Variant (report)
- bleepingcomputer.com — Free Decryptor Released For Donex Muse And Darkrace Ransomware (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Donex (report)
- dissect.ing — Donex (report)
- dissect.ing — Donex Pt2 (report)
- isc.sans.edu — 30812 (report)
- shadowstackre.com — Donex (report)