DisclosureLens
← All groups

dan0n

Active since 2024-03-26
33 claimed victims

Unverified threat-actor claim — not a regulatory filing

Attribution, victim identity, and counts shown here derive from dan0n's public extortion-blog claims, aggregated by ransomware.live. They have not been validated by the victim or any regulator. Treat them as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.

According to ransomware.live, the group claims:

dAn0n emerged in early 2024 operating a RaaS model, rapidly claiming 13 victims in May 2024 alone, predominantly targeting US-based organizations in business services and filling the vacuum left by disruptions to LockBit and BlackCat/ALPHV.

Source: Ransomware.live

Dan0n ransomware group · DisclosureLens