Skip to content
CTI Academy Sponsor CTI Academy
Ransomware group

Dan0n ransomware

33 victims listed on the Dan0n leak site across 3 countries. Most recent disclosure .

Victims
33
0.1% of all tracked
Countries
3
Most: United States
Sectors
6
Most: Business Services
First seen
Apr 2024
In this database

ThreatAI analysis

Compiled from the ransomware.live profile for Dan0n and from this database. Figures and technique mappings are quoted from the source data, not inferred.

Who Dan0n is

dAn0n emerged in early 2024 operating a RaaS model, rapidly claiming 13 victims in May 2024 alone, predominantly targeting US-based organizations in business services and filling the vacuum left by disruptions to LockBit and BlackCat/ALPHV.

Recorded activity

Disclosures attributed to Dan0n in this database run from April 2024 to August 2024, totalling 33 victims — 0.1% of everything tracked here. Dan0n has listed victims in 3 countries in this database, most often United States, followed by Ireland and South Korea. The sectors appearing most in its listings are Business Services, Technology, Healthcare.

YARA detection rules

dAn0n.yar
/*
dAn0n ransomware
*/

rule dAn0n_Ransomnote
{
    meta:
        author = "ransomware.live"
        family = "ransomware.dan0n"
        description = "Detects dAn0n ransomware ransom note or artifact"
        date = "2026-05-04"
        severity = 7
        score = 70

    strings:
        $name1 = "dAn0n" ascii nocase
        $name2 = "DAN0N" ascii
        $onion  = "dan0n.onion" ascii nocase

    condition:
        any of them
}

Community-contributed rules for Dan0n, reproduced as published. Test them against your own corpus before relying on them: rule quality and false-positive behaviour vary by author.

Threat actor analysis

Dan0n has disclosed 33 victims on its leak site, 0.1% of all ransomware listings tracked in this database. Its earliest disclosure here dates to April 2024.

The group has listed organisations in 3 countries, most often in United States (30 victims), followed by Ireland, South Korea.

By industry, its listings concentrate in Business Services, Technology, Healthcare — sectors that hold sensitive data or cannot tolerate long outages, both of which raise the pressure to pay.

Like most current ransomware operations, Dan0n is likely to use double extortion: data is stolen before files are encrypted, and organisations that refuse to pay are named on the leak site with the stolen data as leverage.

Dan0n victims 33

Organization Disclosed
www.seaeng.com
KRSouth Korea
mmtransport.com
USUnited States
www.dunnsolutions.com
USUnited States
thesourcinggroup.com
USUnited States
promarkbrands.com
USUnited States
fifcousa.com
USUnited States
allenblastingandcoating.com
USUnited States
college-park.com
USUnited States
ekiconsult.com
USUnited States
fightingforfairness.com
USUnited States
glenwoodnyc.com
USUnited States
iiexperts.com
USUnited States
neosmteam.com
USUnited States
oconnellmahon.ie
IEIreland
pedsurology.com
USUnited States
s-f-concrete.com
USUnited States
semilab.com
USUnited States
theblakefirm.com
USUnited States
ueg1.com
USUnited States
Pediatric Urology Associates
USUnited States
S&F Concrete Contractors
USUnited States
College Park Industries
USUnited States
Glenwood Management
USUnited States
Northeast Orthopedics and Sports Medicine
USUnited States
Information Integration Experts
USUnited States
Erler & Kalinowski
USUnited States
Allen Blasting and Coating
USUnited States
O'Connell Mahon Architects
IEIreland
Pedsurology
USUnited States
RSH legal
USUnited States
Semilab
USUnited States
The Blake Law Firm
USUnited States
United Equitable Group
USUnited States

Frequently asked questions

What is Dan0n ransomware?

Dan0n is a ransomware threat group that has claimed 33 victims since its first known activity in April 2024. The group operates by infiltrating target networks, exfiltrating data, encrypting files, and threatening to publish stolen data on a dark web leak site if the ransom is not paid.

How many victims has Dan0n attacked?

Dan0n has claimed 33 victims in our database, representing 0.1% of all tracked ransomware attacks. The most targeted countries are United States, Ireland, South Korea.

Which countries does Dan0n target?

Dan0n has attacked organizations in 3 countries. The top targeted countries are: United States, Ireland, South Korea.

Which industries does Dan0n target?

Dan0n most frequently targets the Business Services, Technology, Healthcare sectors based on victim disclosures in our database.

Is Dan0n still active?

Dan0n's most recent victim disclosure in our database was on August 23, 2024. Ransomware groups frequently rebrand or go dormant; monitor this page and our ransomware map for the latest activity.