Helldown Leaks is a ransomware group observed since at least early August 2024 conducting encryption attacks against companies internationally. Reported intrusions have consistently involved Zyxel firewalls as the apparent initial access vector, including cases where affected devices were fully patched. Based on the available facts, the group is associated with ransomware activity and initial compromise leading to encryption of victim environments. No high-confidence attribution to a specific country, broader victimology by sector or geography, or additional confirmed aliases and sub-groups is currently available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.