Helldown — Ransomware Profile
Helldown is a ransomware crew that CYFIRMA first identified in August 2024, and which pressures victims by naming them on its own leak site. Sekoia's analysis found its Windows encryptor is built from the leaked LockBit 3 source code; the same report noted strong similarities to the earlier Darkrace and Donex families but declined to confirm that Helldown is a rebrand of either. A Linux build aimed at VMware ESX servers was first documented on 31 October 2024, extending the operation beyond Windows estates. Truesec's CSIRT, engaged on Helldown intrusions during October 2024, found the operators getting in mainly through Zyxel firewalls before running an encryptor named hellenc.exe. Sekoia traced that activity to a path-traversal flaw it caught on its own honeypots, which Zyxel then acknowledged as CVE-2024-11667 and CISA added to its Known Exploited Vulnerabilities catalog on 3 December 2024. Targeting was sector-agnostic and skewed to small and medium-sized businesses — 31 victims by early November 2024 — and the tracked leak site has posted nothing since 6 November 2024, so the operation appears dormant rather than ongoing.
Vendor research
Read the full analysis on IntelFusions