CSIDB logo
Threat actor

Dunghill

Attribution profile

Type
Crime Syndicate
Location
China
Known incidents
3 incidents
First seen
2022-09-01
Last seen
2023-09-22
Updated
2026-08-01 07:10
Aliases
2 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor known as Dunghill, also tracked as Dark Angels, is linked to China according to the provided context. It operates under two aliases that have been used interchangeably in public reporting. The group has been observed targeting sectors such as building automation, technology manufacturing for automotive and aerospace, and large‑scale engineering firms involved in infrastructure, energy and transport. Victims have been located in the United States and Brazil, with the actor claiming to have shared stolen data with manufacturers from China, India and the United States. Its stated goals involve financial gain, as seen in ransom demands and the use of leaked data to pressure victims into payment.

The actor’s tactics include deploying ransomware that encrypts VMware ESXi servers, as demonstrated in the Johnson Controls incident. Initial access has been achieved through the exploitation of unpatched server vulnerabilities, notably in the Brazilian conglomerate case where the flaw allowed retrieval of municipal and state tax authority credentials hidden in email. After compromising a network, the group exfiltrates large volumes of data—ranging from several terabytes to over twenty‑seven terabytes—and publishes the material on dark web leak sites hosted via Tor. To increase pressure, the actors contact competitors, media outlets and even family members of victims, and they have leaked sensitive photo and video footage obtained during intrusions. The group also rebranded from Dark Angels to Dunghill, presenting itself as a collection of computer specialists.

Representative operations attributed to the actor are the September 2023 ransomware attack on Johnson Controls, the April 2023 data breach at Gentex Corporation, and the September‑October 2021 intrusion that stole three terabytes from the Brazilian engineering firm Andrade Gutierrez. In each case the actor demanded payment, threatened to release or actually released stolen information, and highlighted the financial motive behind the activity. No public source cited in the material establishes a direct state sponsorship or links the group to a larger criminal consortium; the descriptions focus on the actor’s self‑characterization as a relatively new, independent ransomware outfit. Consequently, the profile is limited to the observable behaviors and publicly reported incidents described above.

Incidents

Attributed incidents are available to members.

3 incidents
CSIDB