Cyber Threat Actor: Dunghill
| Actor Type | Location | Known Incidents |
Criminal
|
China
|
3 incidents |
|---|
Profile
The threat actor tracked under the aliasesDunghill and Dark Angels has been observed operating from China, according to the limited location information available in open sources. The group first gained attention as Dark Angels before rebranding to Dunghill in early 2023, a shift noted by Zscaler when the actors launched a new data leak site and adopted the Dunghill name. Their activity spans multiple industries, including building automation, technology manufacturing for automotive and aerospace sectors, and large‑scale engineering conglomerates involved in infrastructure, energy, oil and gas, and transport. Victims have been located in the United States, Brazil, and potentially other regions, indicating a geographically diverse targeting pattern that is not confined to a single country or sector.
Financially motivated extortion appears to be a primary objective, as demonstrated by the ransom demand of $51 million issued to Johnson Controls International after the encryption of its VMware ESXi servers and the claim of exfiltrating over 27 terabytes of data. In the Gentex incident, the actors exfiltrated emails, client documents, and employee personal data, then leaked the material on the dark web and asserted they had shared the stolen information with manufacturers in China, India, and the United States to increase pressure on the victim. The Brazilian conglomerate breach involved the theft of three terabytes of corporate and employee data, including passport details, tax IDs, health insurance records, and sensitive project blueprints, obtained through exploitation of an unpatched server vulnerability that allowed access to municipal and state tax authority credentials hidden within emails. Observed tactics, techniques, and procedures include ransomware deployment against virtualized environments, exploitation of unpatched servers for initial access, and the use of Tor‑hosted leak sites to publish stolen data and coerce payment. No public attribution to a state sponsor or criminal alliance has been established, and the group’s internal structure, size, or revenue remains unspecified in the available reporting. The combination of ransomware encryption, large‑scale data theft, and public leak sites represents the core of their operational pattern as evidenced by the Johnson Controls, Gentex, and Brazilian conglomerate incidents.
