← Back to Ransomware Chk

Dagonlocker

Inactive
Dagon Locker is a ransomware strain that first appeared in early 2023, evolved from the MountLocker/Quantum ransomware lineage, and uses IcedID as an initial access vector before deploying double-extortion attacks with ChaCha20+RSA-2048 encryption.
0 Victims
0% Infostealer
0/1 Sites Online
Known Locations (1)
The Chat
dgnh6p5uq234zry7qx7bh73hj5ht3jqisgfet6s7j7uyas5i46xfdkyd.onion
Tools Used
DiscoveryEnum
AdFind, Nbtscan, Seatbelt, ShareFinder, SoftPerfect NetScan
Exfiltration
RClone
Offsec
Cobalt Strike
RMM-Tools
AnyDesk
Victims (0)

Detailed victim list temporarily unavailable

This group has 0 victims. The victim list API is currently responding slowly for this dataset. Country, sector, and infostealer breakdowns are not available at this time. Basic stats (victim count, first/last seen) are shown above from a faster data source.