Helldown is a ransomware and extortion threat group that emerged prominently in late 2024 and remained active into 2025 as part of the volatile post-LockBit ransomware ecosystem. It has been identified as a rising ransomware operation and appears to have conducted rapid intrusions against small and medium-sized enterprises in Europe, including campaigns involving Zyxel firewall environments and virtualization infrastructure. Observed Helldown intrusions show fast execution from initial access to encryption, including access through Zyxel SSL VPN services, internal discovery with network-scanning utilities, credential theft using tools such as Mimikatz and manual extraction from enterprise software configuration stores, malware-less lateral movement over Remote Desktop, and direct deployment of ransomware on ESXi hosts to encrypt virtualized environments. In some cases, operators modified firewall access-control rules to reduce segmentation and improve internal reach, then targeted backup infrastructure and hypervisors. Reporting also links Helldown activity to use of HRSword during encryption operations and to discovery tooling such as Advanced Port Scanner. Technical reporting indicates overlap between an earlier 2024 extortion wave using the identifier “unitui57” and later Helldown-attributed operations, particularly in ESXi locker tooling and encryption logic. This suggests either operational continuity, a shared cluster, or an evolution of branding over time. Helldown has also been associated with data theft claims and public extortion behavior consistent with modern ransomware operations. The group is best characterized as a financially motivated ransomware actor using credential theft, internal reconnaissance, lateral movement, defense evasion, and virtualization-focused encryption to pressure victims.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
10 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Rising ransomware group; noted using credential theft and scanning tooling.
Ransomware/extortion operations targeting European SMEs via Zyxel SSL VPN access, using rapid hands-on-keyboard intrusion, malware-less lateral movement, credential harvesting, firewall ACL changes, and ESXi encryption. The later wave is explicitly attributed to Helldown, and the report assesses the earlier September ESXi locker activity as likely attributable to the same organization.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.