donex

First seen
2024-03-15 00:00:00
Malware type
ransomware
Family
Malware family
Profile updated
2026-07-07 13:51:12

Targeted industries: financial-services healthcare-and-pharmaceutical government-and-public-sector

Context

The ransomware group known as DoNex was first identified in mid-March 2024. According to the data collected, the samples used by the group were compiled in mid-February, suggesting that it is a relatively new operation.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Donex_Auto (yara-rule)

Related threat objects

Reports & references

  • helpnetsecurity.com — Decryptor Donex Muse Darkrace Fake Lockbit 3 0 (report)
  • ransomlook.io — Donex (report)
  • fortinet.com — Ransomware Roundup Keganohitobito And Donex (report)
  • Trend Micro — New Donex Ransomware Variant (report)
  • bleepingcomputer.com — Free Decryptor Released For Donex Muse And Darkrace Ransomware (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Donex (report)
  • dissect.ing — Donex (report)
  • dissect.ing — Donex Pt2 (report)
  • isc.sans.edu — 30812 (report)
  • shadowstackre.com — Donex (report)

External references