dAn0n
dAn0n emerged in early 2024 operating a RaaS model, rapidly claiming 13 victims in May 2024 alone, predominantly targeting US-based organizations in business services and filling the vacuum left by disruptions to LockBit and BlackCat/ALPHV.
dAn0n is a 2024 RaaS cybercriminal group filling the void left by LockBit disruptions.
dAn0n is a cybercriminal group that emerged in early 2024, operating under a RaaS model and rapidly claiming victims to fill the void left by disruptions to LockBit and BlackCat/ALPHV. It predominantly targets US-based organizations, specifically within the business services sector. While specific TTPs are not detailed in the provided data, as a RaaS affiliate-driven operation, they likely employ a variety of common ransomware distribution methods and dual-use tools for initial access and lateral movement. Defenders, especially those in US business services, should prioritize hardening against common initial access vectors like phishing and exposed RDP, and ensure robust ransomware-specific defenses are in place.
dAn0n emerged in early 2024 operating a RaaS model, rapidly claiming 13 victims in May 2024 alone, predominantly targeting US-based organizations in business services and filling the vacuum left by disruptions to LockBit and BlackCat/ALPHV.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.