Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Desolator

| RaaS

Desolator is a ransomware group that emerged in May 2025, targeting construction and engineering firms in Latin America and Europe and technology companies in Asia, actively recruiting pen testers, initial access brokers, and social engineers via dark web forums to build an affiliate program.

Victims
4
 
First Discovered
2025-08-30
victim
Last Discovered
2025-09-01
victim
Inactive Since
262
days
Avg Delay
2.5
days
Infostealer
33.3%
victims with domain
Countries
3
hit
View Victims on World Map View Group Statistics
Attack Velocity — Last 12 months

Known Locations (1)
Favicon Title Type Available Last Visit Server Info FQDN
favicon Wall of Shame - Non-Compliant Targets No 2026-04-28T07:23:36 po4tq2brx4rgwbdx4mac24fz34uuuf7oigosebp32n2462m2vxl6biqd.onion

Target
Top 5 Activity Sectors
  • Construction 2
  • Financial Services 1
  • Technology 1
Top 5 Countries
  • CO flag Colombia 2
  • US flag United States 1
  • VN flag Viet Nam 1

Heatmap

YARA Rules (1)

Victims (4)
Logo
Discovered: 2025-09-01 (8mo ago)  ·  Attack est.: 2025-08-28
Status: waiting | Expiration: 2025-09-04T00:00…
Logo
Discovered: 2025-09-01 (8mo ago)  ·  Attack est.: 2025-08-31
Status: waiting | Expiration: 2025-09-05T00:00…
Logo
Discovered: 2025-08-30 (8mo ago)  ·  Attack est.: 2025-08-27
Status: waiting | Expiration: 2025-09-01T00:00…
Logo
Discovered: 2025-08-30 (8mo ago)  ·  Attack est.: 2025-08-28
Status: waiting | Expiration: 2025-09-04T00:00…