Ransomware Group intelligence
Helldown
InactiveTrack Helldown with 37 published victims and 2 known leak locations in a single intelligence view.
Overview
Helldown is tracked by Breach House as a ransomware group with 37 published victims.
United States is currently the most targeted country in this dataset.
2 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (2)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Unknown | onyxcgfg4pjevvp5h34zvhaj45kbft3dg5r33j5vu3nyp7xic3vrzvad.onion |
| Leak location 2 | Onion service | Unknown | onyxcym4mjilrsptk5uo2dhesbwntuban55mvww2olk5ygqafhu3i3yd.onion |
Top Activity Sectors
No sector intelligence available.
Ransom Notes (0)
▼No ransom notes available for this group.
Tools Used
▼No tools used available.
YARA Rules (0)
▼No YARA rules available.
Indicators of Compromise (0)
▼No IoCs available for this group.
Negotiation Chats (0)
▼No negotiation chats available.
Research Sources
No external research sources linked yet.
Victims (37)
Search, filter and paginate the victim timeline for Helldown.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | klinkamkurpark id15199 View details | Germany | Other | ||
|
klinik-am-kurpark.de |
|||||
| Ransomware | hausdesstiftens.org id15198 View details | Germany | Other | ||
|
hausdesstiftens.org |
|||||
| Ransomware | nightnurse.ch id15197 View details | Switzerland | Other | ||
|
www.nightnurse.ch |
|||||
| Ransomware | fuelco id15196 View details | Energy | |||
|
fuelco-us.com |
|||||
| Ransomware | VALLEYFIRM id15195 View details | Hong Kong | Other | ||
|
valleyfirm.com |
|||||
| Ransomware | children id15194 View details | India | Other | ||
|
generaldentistryforchildren.com |
|||||
| Ransomware | knoxlawcenter id15193 View details | United States | Finance / Legal / Insurance | ||
|
www.knoxlawcenter.com |
|||||
| Ransomware | AMERICANVENTURE id15192 View details | United States | Other | ||
|
americanventures.com |
|||||
| Ransomware | CSIKBS id15191 View details | Japan | Other | ||
|
www.csikitchenandbath.com |
|||||
| Ransomware | SANJACINTOCOUNY id15190 View details | United States | Other | ||
|
www.co.san-jacinto.tx.us |
|||||
| Ransomware | compassfs id15189 View details | United States | Other | ||
|
www.compassfs.net |
|||||
| Ransomware | lacliniqueducoureur id15188 View details | Canada | Other | ||
|
lacliniqueducoureur.com |
|||||
| Ransomware | TIVOLI-33 id15187 View details | France | Other | ||
|
tivoli-33.org |
|||||
| Ransomware | qualiform.cz id15186 View details | Czechia | Other | ||
|
www.qualiform.cz |
|||||
| Ransomware | SMARTS-ENGINEER id15185 View details | Russian Federation | Manufacturing / Engineering | ||
|
www.smarts-engineering.de |
|||||
| Ransomware | HBGJEWISHCOMMUN id13970 View details | United States | Other | ||
|
www.jewishharrisburg.org |
|||||
| Ransomware | barryavenueplating id13962 View details | United States | Hospitality / Food & Beverage / Tourism | ||
|
www.barryavenueplating.com |
|||||
| Ransomware | rsk-immobilien id13961 View details | Germany | Other | ||
|
www.rsk-immobilien.de |
|||||
| Ransomware | cincinnatipainphysicians id13949 View details | United States | Services | ||
|
www.cincinnatipainphysicians.com |
|||||
| Ransomware | kbosecurity.co.uk id13936 View details | United Kingdom | Other | ||
|
kbosecurity.co.uk |
|||||
| Ransomware | khonaysser.com id13935 View details | Lebanon | Other | ||
|
khonaysser.com |
|||||
| Ransomware | BARRYAVEPLATING id13922 View details | United States | Hospitality / Food & Beverage / Tourism | ||
|
BARRYAVEPLATING |
|||||
| Ransomware | RSK-IMMOBILIEN id13921 View details | Germany | Other | ||
|
RSK-IMMOBILIEN |
|||||
| Ransomware | ATP id13905 View details | Italy | Other | ||
|
atpsassari.it |
|||||
| Ransomware | Khonaysser id13896 View details | Lebanon | Other | ||
|
Khonaysser |
|||||
| Ransomware | kbo id13890 View details | United Kingdom | Other | ||
|
Here's something encrypted, password is required to continue reading. |
|||||
| Ransomware | zyxel id13867 View details | Netherlands | IT | ||
|
Zyxel.eu is a European branch of Zyxel Communications Corporation, a global leader in networking solutions. It specializes in providing innovative and reliable internet connectivity products and services, including routers, switches, security appliances, and cloud-based network management systems. Zyxel focuses on empowering businesses and home users with cutting-edge technology to enhance their digital experiences. |
|||||
| Ransomware | hugwi id13824 View details | Switzerland | IT | ||
|
Hugwi.ch is a Swiss-based company specializing in providing cutting-edge digital solutions, with a focus on web development, e-commerce, and custom software. They offer tailored services to businesses, enhancing their online presence and operational efficiency. Known for their innovation and customer-centric approach, Hugwi.ch combines technical expertise with creative design to deliver high-quality, scalable solutions that meet diverse client needs. |
|||||
| Ransomware | SCHLATTNER id13810 View details | Germany | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | deganis id13809 View details | France | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | XPERT Business Solutions GmbH id13802 View details | Austria | Services | ||
|
No additional victim description available. |
|||||
| Ransomware | MyFreightWorld id13801 View details | United States | Transportation / Travel / Logistics | ||
|
No additional victim description available. |
|||||
| Ransomware | cbmm id13800 View details | Brazil | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | AZIENDA TRASPORTI PUBBLICI S.P.A. id13799 View details | Italy | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | briju id13798 View details | Poland | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | vindix id13797 View details | Poland | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | Albatros id13796 View details | Italy | Other | ||
|
No additional victim description available. |
|||||