DoNex attacks MIREL

Incident Date: Mar 08, 2024

Attack Overview
VICTIM
Mission Régionale pour l'Emploi de Liège (MIREL)
INDUSTRY
Government
LOCATION
Belgium
ATTACKER
Donex
FIRST REPORTED
March 8, 2024

The Regional Mission for Employment in Liege Targeted by Ransomware

The Regional Mission for Employment in Liege (MIREL) has been targeted by the DoNex ransomware group. The attack allegedly exfiltrated 19 GB of data, including forms, work certificates, application letters, and more. MIREL’s aim is to match job supply and demand. It offers a range of services for businesses and job seekers.

DoNex: A New Threat on the Horizon

DoNex is a new ransomware group actively targeting entities in the United States and Europe. The group has begun listing companies as its victims on its dark web portal, accessible via the Onion network. The group’s tactics are especially insidious, employing a double-extortion method, which encrypts files, which are then appended with a unique VictimID extension. The group also exfiltrates sensitive data and holds it hostage to leverage additional pressure on the victims to pony up the ransom.

How DoNex Operates

In line with the typical behavior of ransomware groups, after encrypting the files, DoNex generates a ransom note on the victim's computer. This note usually appears as either a text file or a pop-up window and includes detailed instructions on how to pay the ransom to get the decryption key. Victims have discovered ransom notes named Readme.VictimID.txt on their systems, which instruct them to establish contact with the DoNex group through Tox messenger, a peer-to-peer instant messaging service known for its security and anonymity features.

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.