Dark Angels is a Russian-speaking cybercriminal ransomware and data-extortion group active since May 2022. It is also referred to as the Dunghill Leak group and operates the Dunghill Leak/Dunghill Leaks data leak site. Reporting in the provided content describes Dark Angels as a human-operated operation that targets companies worldwide and follows a big-game-hunting model, typically focusing on a small number of high-value victims at a time rather than broad indiscriminate targeting. The group is described as breaching corporate networks, moving laterally until it obtains administrative access, stealing data from compromised servers for extortion, and then deploying ransomware after gaining access to a Windows domain controller. In at least one 2024 case, Zscaler stated Dark Angels did not deploy ransomware and the victim paid solely to prevent publication of stolen data, indicating the group also conducts pure data-extortion operations. The content also associates Dark Angels with targeting VMware ESXi environments. Dark Angels initially used Windows and VMware ESXi encryptors based on leaked Babuk source code and later switched to a Linux encryptor described as the same one used by Ragnar Locker. The group has used ransomware variants from other groups, including Ragnar Locker. The content links Dark Angels to the 2023 Johnson Controls incident, where it allegedly encrypted VMware ESXi virtual machines, claimed to steal more than 27 TB of data, and demanded $51 million. The most prominent reporting in the content concerns a record-breaking ransom payment in early 2024: a Fortune 50 U.S. company reportedly paid Dark Angels $75 million after the group exfiltrated approximately 100 TB of data. Chainalysis is cited as confirming this as the largest ransomware payment ever recorded. Separate reporting cited in the content suggests, but does not confirm, that the victim may have been Cencora. Known alias/sub-group naming in the content: Dunghill Leak group; Dunghill Leak/Dunghill Leaks.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware operations described as using ESXi-specific variants and refined hypervisor targeting, including backup destruction and high-impact disruption.
Dark Angels is a ransomware group known for demanding and receiving large ransom payments, such as the reported $75 million, which has influenced the broader ransomware ecosystem to pursue higher payouts.
Conducting large-scale data theft and extortion operations, including theft of massive data volumes from major corporations.
Ransomware/extortion group associated in the content with a record-breaking $75 million ransom payment in H1 2024.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.