Doommageddon is a ransomware and data-theft extortion group that emerged in 2026. It has been publicly associated with leak-site style victim disclosures and extortion deadlines, including incidents marked as upcoming, leaked, and negotiated. Reported victimology indicates activity against organizations in healthcare, financial services, business services, and consumer services, with observed targets in Brazil, Paraguay, and the United States. The group has been linked to attacks on healthcare entities including Hospital Di Camp and Reni Farmácias Associadas, as well as financial-sector and other commercial organizations. The actor’s operations show a strong extortion component centered on stolen-data exposure. In at least one case, the group claimed a staged, multi-wave release of allegedly stolen medical information, beginning with limited disclosure and threatening broader publication of protected health information, personal data, and full databases. This pattern is consistent with data-theft extortion conducted through public leak infrastructure rather than confirmed encryption-focused operations. Available reporting supports the use of ransomware branding and coercive deadlines, but does not provide high-confidence technical detail on malware deployment, intrusion vectors, or post-compromise tradecraft beyond public shaming and threatened data release. Known aliases are limited to the lowercase form doommageddon.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A newly emerged data theft/ransomware group.
Conducting a ransomware attack against Reni Farmácias Associadas.
Claims to have breached Hospital Di Camp in Brazil and is conducting a staged three-wave leak of allegedly stolen patient and hospital data, beginning with ECG data and followed by PHI, PII, and full databases.
Conducting a ransomware attack against a healthcare organization in the United States.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.