Tracking the Doommageddon Ransomware Campaign

Doommageddon is a ransomware operation driven by financial gain. It follows the well-established double-extortion approach: attackers first steal sensitive data, then encrypt affected systems, and finally threaten to release the stolen information unless a ransom is paid. One particularly notable aspect of Doommageddon is how long the group managed to remain largely unnoticed.

According to Cynet’s investigation, the earliest identified intrusion linked to the group occurred on March 8, 2026. However, Doommageddon did not establish a public presence until July 6. On that date, the operators launched a Tor-based data leak website and simultaneously listed six victims. Each listing referred to an intrusion that had taken place several weeks or even months before the website appeared.

This pattern is not unprecedented.

A previous CyOps investigation into DeadLock’s discreet extortion activities identified another ransomware operation that functioned for months without maintaining a conventional public leak website. Instead, its operators primarily communicated with victims directly. When CyOps examined DeadLock’s integrated victim portal, it contained 29 pages documenting 87 victims. DeadLock has continued developing this relatively discreet operational approach. Its newer techniques include using Session and blockchain-based infrastructure to make certain components of its extortion activities more resistant to disruption.

Although Doommageddon differs from DeadLock in its infrastructure and execution methods, both operations illustrate the same broader issue: public exposure does not reliably reflect the actual scale of ransomware activity. Threat actors may compromise numerous organizations, improve their malicious tools, and negotiate with victims for extended periods before their activities become apparent through public leak websites.

Furthermore, Doommageddon remained active after Cynet published its August investigation. By September 30, independent monitoring services had documented at least 14 claims involving victims listed on the group’s leak site. The most recent recorded activity occurred on September 28. Manufacturing accounted for the largest share of listed organizations, followed by healthcare and several additional industries. Importantly, these entries represent claims made by the attackers rather than independently verified security breaches.

A Patient Approach to Extortion

For the victims examined in Cynet’s August Cyberthreat Intelligence Report, the average interval between an initial Doommageddon intrusion and the corresponding appearance on its leak website was 57 days. Consequently, data theft, system encryption, and ransom negotiations could already be progressing or even concluded by the time an incident becomes publicly known.

Doommageddon also increases pressure on affected organizations by publishing stolen information in stages. In one incident involving a Brazilian healthcare organization, the attackers announced plans to disclose the victim’s records across three separate releases instead of making the entire dataset available immediately.

Rather than relying on standard email correspondence or a purpose-built negotiation website, the group communicates with victims through Session, an encrypted messaging application. DeadLock has similarly made extensive use of Session. This reflects a broader tendency among ransomware operators to adopt communication methods that reduce their dependence on conventional email systems and web-based negotiation infrastructure.

Doommageddon Ransom Note requesting contact via Session
However, one of the most significant findings for security teams concerns a capability entirely absent from the Doommageddon encryptor.

The malware has no built-in networking functionality. It cannot communicate with an external command-and-control server, obtain an encryption key remotely, or transfer stolen information outside the compromised environment. This strongly suggests that data exfiltration is performed independently, through other tools deployed before the encryption phase.

For security teams, this makes the earlier stages of the intrusion particularly important for detection. Before the encryptor begins operating, attackers may have already navigated the compromised infrastructure, collected and prepared confidential data, transferred it outside the organization, and initiated extortion negotiations.

Isolating a compromised endpoint after encryption begins may prevent the attack from spreading further. However, isolation cannot reverse encryption that is already taking place on the affected machine’s local storage. Additionally, Doommageddon destroys event logs only on the compromised host. As a result, remote file servers may still preserve their own records of malicious activity.

Static Analysis

The malware sample investigated by CyOps is a 64-bit Windows executable developed in Rust and configured as a GUI application. This design allows the program to operate without opening a visible console window.

The executable references 166 imported functions across 16 Windows libraries, with all imports explicitly represented in its import table. This structure suggests that the malware has not undergone extensive packing or obfuscation. Its imported functions also support interaction with network shares, indicating that the encryptor was designed to access shared storage across the network rather than operate exclusively on locally stored files.

Two Windows API functions are especially noteworthy: CloseEventLog and ClearEventLogW.

Doommageddon intentionally erases Windows event logs during execution. This activity removes potentially valuable forensic evidence from the infected machine and complicates efforts to reconstruct the incident afterward.

Paths to compiled source files preserved within the executable provide additional information about its encryption mechanisms. Contrary to the ransom note’s assertion that RSA is the sole encryption algorithm, Doommageddon combines ChaCha20-Poly1305 for encrypting file contents with RSA for securing the generated encryption keys.

A new encryption key is generated individually for every file. Each key is subsequently secured using a public key embedded in the executable. Without access to the corresponding private key controlled by the attackers, recovering the encrypted files is impractical.

The malware also includes a hardcoded list of 16 Windows event logs scheduled for deletion. These include PowerShell, RDP, Terminal Services, and other logs containing information about system operations.

Related functionality focuses on disabling recovery options and terminating software that could obstruct encryption. Before processing files, Doommageddon closes database services, email applications, backup software, and Microsoft Office programs. Terminating these processes releases files that might otherwise remain inaccessible to the encryptor because they are locked by active applications.

Dynamic Analysis

When launched, the ransomware attempts to restart itself with elevated privileges by invoking the Windows shell. It uses the path of its existing executable rather than installing or launching an additional privilege-elevation utility.

The malware subsequently disables the Hyper-V shadow copy requestor, identifies shared disks accessible over the network, and executes vssadmin to remove shadow copies. This method of obstructing recovery is common among ransomware families. By deleting shadow copies, attackers eliminate a potential restoration option that organizations might otherwise use to recover affected data.

For every file selected for encryption, Doommageddon obtains 32 bytes of cryptographically secure random data through the Windows BCrypt API. These bytes are used to establish a unique 256-bit ChaCha20 encryption key for that particular file. Therefore, the ransomware does not rely on a single encryption key throughout the entire execution process.

Doommageddon does not simply overwrite files in place

The observed file-writing behavior also demonstrates that Doommageddon does not encrypt data by directly overwriting the original files. Instead, it creates a new file containing the encrypted ciphertext, adds the .doomag extension, and subsequently deletes the original file.

Once encryption is complete, the ransomware proceeds to clear the same 16 Windows event logs identified during the static examination. It also creates a ransom note named README_DECRYPT.txt.

it targets the same 16 Windows event logs identified during static analysis and drops its ransom note

The Leak Site: Why Victim Numbers Are Difficult to Reconcile

A relabeled victim entry showing “PAID” “DATA SECURED” status.

Doommageddon’s public leak website operates according to a familiar ransomware extortion strategy. Organizations are identified by name, and where available, visitors can access files that the attackers claim to have obtained during their intrusions.

However, Cynet identified an unusual detail concerning how the group handles entries associated with organizations that seemingly entered negotiations or made ransom payments.

Instead of removing these organizations from the website entirely, the operators replaced certain victim names and identifying information with the word “PAID.” The corresponding entries received updated status indicators, including “NEGOTIATED” and “DATA SECURED.” At the same time, the number of files displayed for those entries was reduced to zero.

This practice makes it particularly difficult to establish an accurate victim count based on Doommageddon’s public website.

A single snapshot can reveal which victim entries are visible at a particular time. However, it cannot necessarily establish the total number of compromised organizations, how many entered negotiations, or how many actually paid a ransom. Independent ransomware monitoring platforms also report differing victim totals. These inconsistencies demonstrate why leak-site statistics should be interpreted as approximate threat intelligence indicators rather than verified counts of security incidents.

This further illustrates the limitations of relying on public exposure to assess ransomware activity. An operation with little public visibility may be considerably more active than it appears. Even when a group maintains a public leak website, that website may reveal only a fraction of its overall operations.

Cynet vs. Doommageddon Ransomware

During controlled simulations, Cynet’s unified cybersecurity platform operated with detection enabled and prevention disabled. This configuration allowed the Doommageddon sample to complete its full attack sequence while researchers examined the platform’s ability to identify the malicious activity.

Cynet identified Doommageddon through several independent detection mechanisms:

  • AV/AI detection: The platform recognized the malicious executable when it was saved to disk or when execution was attempted.
  • Threat intelligence: External threat intelligence sources separately classified the file as malicious.
  • Process monitoring: Cynet identified the attempt to delete shadow copies through vssadmin by examining the process behavior and associated command-line arguments.
  • Unauthorized memory access detection: Suspicious attempts to obtain handles providing access to another process’s memory triggered detection.
  • Ransomware protection: Monitoring of file operations revealed the unusual .doomag extension and attempts to write to decoy files deployed by Cynet’s ransomware protection mechanism.

Although the encryption phase produces some of the most obvious signs of compromise, it does not necessarily represent the earliest stage at which the attack can be stopped. For Doommageddon, the absence of network communication capabilities within the encryptor strongly indicates that data exfiltration and other malicious operations are conducted through separate components or tools. This creates multiple potential detection opportunities before attackers reach the final, destructive stage of their operation.

A comparable security principle emerged from Cynet’s recent investigation into Settra ransomware. Settra employed substantially more sophisticated methods to conceal its malicious executable than Doommageddon. Specifically, its encryptor was embedded within an encrypted payload protected by a password. Nevertheless, once the malware started interacting with the operating system to encrypt information, behavioral security mechanisms still had an opportunity to recognize and interrupt the attack.

What’s in a Name?

Doommageddon has not achieved the same prominence as some of the ransomware landscape’s more established groups. Nevertheless, Cynet’s investigations into both Doommageddon and DeadLock demonstrate how extensive malicious activity can remain undetected by the public before a ransomware operation attracts significant attention. Public leak websites, reported victim totals, and prominent announcements provide valuable threat intelligence. However, they typically reflect activity that has already occurred rather than offering an immediate picture of an ongoing campaign.

The most effective opportunities to disrupt a ransomware attack generally arise before a ransom note is created. Relevant warning signs include unusual system access, privilege escalation, lateral movement, attempts to disable recovery mechanisms, data collection and staging, exfiltration, suspicious process activity, and unexpected file operations. Identifying the specific ransomware group responsible for an incident may provide useful context, but security teams cannot afford to delay their response until that attribution is established.

Get Cynet Demo



    Subscribe to news