Skip to content

helldown

Inactive

25 tracked victims · First seen Aug 5, 2024 · Last seen Nov 6, 2024

About

Aggregated threat-intel description

Helldown is an aggressive ransomware group first documented in August 2024, known for exploiting Zyxel firewall vulnerabilities to gain initial access and conducting large-scale data exfiltration averaging 70 GB per victim, targeting IT services, telecommunications, manufacturing, and healthcare primarily in the US.

Sectors: Business Services, Manufacturing, Healthcare · Countries: US, DE, IT

Recent victims

View all →
VictimSectorCountryPostedStatus
klinkamkurparkNot FoundDENov 6, 2024
hausdesstiftens.orgNot FoundDENov 6, 2024
nightnurse.chHealthcareCHNov 6, 2024
fuelcoEnergyNov 6, 2024
VALLEYFIRMNot FoundHKNov 6, 2024
childrenNot FoundINNov 6, 2024
knoxlawcenterBusiness ServicesUSNov 6, 2024
AMERICANVENTURENot FoundUSNov 6, 2024
CSIKBSNot FoundJPNov 6, 2024
SANJACINTOCOUNYNot FoundUSNov 6, 2024
compassfsFinancialUSNov 6, 2024
lacliniqueducoureurHealthcareCANov 6, 2024
TIVOLI-33Not FoundFRNov 6, 2024
qualiform.czManufacturingCZNov 6, 2024
SMARTS-ENGINEERTechnologyRUNov 6, 2024
HBGJEWISHCOMMUNGovernmentUSAug 24, 2024
barryavenueplatingManufacturingUSAug 23, 2024
cincinnatipainphysiciansHealthcareUSAug 22, 2024
kbosecurity.co.ukBusiness ServicesGBAug 22, 2024
khonaysser.comEnergyLBAug 22, 2024
BARRYAVEPLATINGManufacturingUSAug 21, 2024
RSK-IMMOBILIENBusiness ServicesDEAug 21, 2024
ATPBusiness ServicesITAug 20, 2024
KhonaysserEnergyLBAug 19, 2024
kboNot FoundGBAug 18, 2024

All ransomware groups · Dark web intelligence