Helldown is an aggressive ransomware group active since 2024, known for exploiting Zyxel firewall vulnerabilities.
Analyst brief
Helldown is an aggressive ransomware group active since August 2024. It primarily targets IT services, telecommunications, manufacturing, and healthcare sectors in the US. The group exploits Zyxel firewall vulnerabilities for initial access and conducts large-scale data exfiltration averaging 70 GB per victim. Defenders should urgently apply security patches for Zyxel devices and strengthen monitoring for signs of abnormal data exfiltration.
helldown
crime
Helldown is an aggressive ransomware group first documented in August 2024, known for exploiting Zyxel firewall vulnerabilities to gain initial access and conducting large-scale data exfiltration averaging 70 GB per victim, targeting IT services, telecommunications, manufacturing, and healthcare primarily in the US.