Back to Threat Groups

donex

INACTIVERansomware-as-a-Service

ransomware group

Donex is a ransomware family that emerged in early 2022 as a rebrand of the older Muse ransomware. It uses a double-extortion strategy, combining file encryption with threats to leak stolen data on a Tor-hosted portal. Written in C++, Donex encrypts files using a combination of ChaCha20 and RSA-4096 algorithms and appends a custom extension unique to each victim. The group targets a broad range of sectors, including manufacturing, logistics, and professional services, with victims reported across North America, Europe, and Asia. Initial access methods include exploitation of public-facing applications and the use of stolen RDP credentials.

Victims
5
records
First Discovered
Mar 8, 2024
victim
Last Discovered
Mar 8, 2024
victim
Inactive Since
935
days
Countries
5
hit
Avg Discount
—
no settlements

Group Activity

Last 12 months
Oct
2025
Nov
2025
Dec
2025
Jan
2026
Feb
2026
Mar
2026
Apr
2026
May
2026
Jun
2026
Jul
2026
Aug
2026
Sep
2026