1H 2026 Examination of Cyber Hostility and Operations

Tracking Doommageddon’s Ransomware Campaign

Doommageddon is a financially motivated ransomware operation built around the now-familiar double-extortion model: steal data first, encrypt systems second, then threaten publication if the victim doesn’t pay. What makes the group interesting is how long it was able to operate in the shadows.

Cynet’s analysis traced the group’s earliest known intrusion to March 8, 2026. But Doommageddon had no public presence until July 6, when it launched a Tor leak site and posted six victims at once, each backdated to a compromise that had already happened weeks or months earlier.

It’s a theme we’ve seen before. In our analysis of DeadLock’s quiet extortion campaign, CyOps found a ransomware group that spent months operating without a traditional public leak site, relying heavily on direct victim communication instead. By the time we analyzed its embedded victim portal, it contained 29 pages covering 87 victims. DeadLock has since continued to evolve its low-profile model, including the use of Session and blockchain-backed infrastructure to make parts of its extortion operation harder to disrupt.

Doommageddon’s infrastructure and execution are different, but the larger lesson is similar: a ransomware group’s public visibility is not a good measure of its activity. Groups can quietly accumulate victims, refine their tooling, and conduct negotiations long before they make a splash on public leak sites.

And Doommageddon hasn’t stopped since Cynet’s August analysis. As of September 30, third-party tracking has recorded at least 14 leak-site claims associated with the group, with the latest activity dated September 28. Manufacturing remains the most represented sector, followed by healthcare and several other industries. These listings are attacker claims, not independently confirmed breaches.

A Patient Extortion Model

In the victim set Cynet analyzed for its August Cyberthreat Intelligence Report, an average of 57 days passed between a Doommageddon intrusion and the victim appearing on the group’s leak site. That means the theft, encryption, and negotiation may be well underway or already complete before the incident becomes visible publicly.

The group also uses staged publication to increase pressure. In one Brazilian healthcare case, Doommageddon advertised a three-wave release of the same victim’s records rather than publishing everything at once.

Victim communication runs through Session, an encrypted messaging application, instead of conventional email or a dedicated negotiation portal. DeadLock has also leaned heavily on Session, another example of ransomware operators adopting communication channels that make their negotiation infrastructure less dependent on traditional email and web services.

Doommageddon Ransom Note requesting contact via Session

But the most important detail for defenders is what the Doommageddon encryptor itself cannot do.

It contains no networking capability. It can’t call home, retrieve a key, or exfiltrate data. That strongly indicates that data theft happens separately, using other tooling before encryption begins.

For defenders, that shifts the most valuable detection window earlier in the attack. By the time the encryptor executes, the attacker may already have moved through the environment, staged sensitive information, exfiltrated data, and begun extortion negotiations.

Once encryption starts, isolating an infected host can help limit the blast radius, but it does not undo encryption already occurring on the local disk. And because Doommageddon’s log destruction is confined to the infected host, remote file servers may retain their own records of the activity.

Static Analysis

The sample analyzed by CyOps is a 64-bit Windows GUI executable written in Rust, allowing it to run without a visible console window.

It imports 166 functions from 16 Windows libraries through a fully populated import table, suggesting the binary is not heavily packed or obfuscated. Its imports also include functionality for accessing network shares, consistent with an encryptor built to reach network-accessible storage rather than limiting itself to the local disk.

Two imported functions stand out: CloseEventLog and ClearEventLogW.

The sample deliberately clears Windows event logs as it runs, removing evidence from the infected host and making post-incident reconstruction more difficult.

Compiled source paths embedded in the binary also reveal more about its cryptography than the ransom note does. Doommageddon uses ChaCha20-Poly1305 for file contents and RSA to protect the generated keys, rather than relying on RSA alone as the ransom note claims.

Each file receives its own freshly generated key. That key is then protected using a public key embedded in the malware, making recovery without the corresponding attacker-controlled private key impractical.

The binary also contains a predefined list of 16 Windows event logs targeted for clearing, including PowerShell, RDP, Terminal Services, and other operational logs.

Nearby logic targets recovery mechanisms and applications that could interfere with encryption. The ransomware shuts down database engines, mail clients, backup agents, and Office applications before encrypting files. Killing those processes releases files that would otherwise remain locked by running applications.

Dynamic Analysis

During execution, the sample relaunches itself with elevated privileges through the Windows shell, using its own executable path rather than deploying a separate elevation tool.

It then stops the Hyper-V shadow copy requestor, enumerates shared disks across the reachable network, and uses vssadmin to delete shadow copies—a recovery-inhibition technique frequently observed across ransomware families. Deleting shadow copies removes one of the recovery paths attackers know defenders may rely on.

Before encrypting each file, Doommageddon requests 32 bytes of cryptographically secure random data through the Windows BCrypt API. That produces a fresh 256-bit ChaCha20 key for the individual file instead of reusing one encryption key across the entire run.

The write pattern also confirms that Doommageddon does not simply overwrite files in place. It writes the encrypted ciphertext to a new file, appends the .doomag extension, and then deletes the original.

After encryption, it targets the same 16 Windows event logs identified during static analysis and drops its ransom note, README_DECRYPT.txt.

The Leak Site: A Victim Count That Doesn’t Add Up Cleanly

The Doommageddon leak site’s victim listing.

Doommageddon’s leak site follows the familiar ransomware pressure model: name organizations publicly and, when available, offer downloads of files the group claims to have stolen.

But Cynet’s review uncovered an interesting wrinkle in how Doommageddon accounts for organizations that appear to negotiate or pay.

Rather than simply disappearing from the site, some entries had their original organization names and details replaced with “PAID.” Their status changed to labels such as “NEGOTIATED” or “DATA SECURED,” while the displayed file count was reset to zero.

A relabeled victim entry showing “PAID” / “DATA SECURED” status.

That makes Doommageddon’s public victim count inherently messy.

A snapshot of the leak site tells you which entries are visible at that moment, but it does not necessarily tell you how many organizations the group has compromised, how many have negotiated, or how many paid. Third-party ransomware trackers also currently report different totals, reinforcing why leak-site numbers are best treated as directional threat intelligence rather than a definitive breach count.

It’s another reason public visibility can be misleading. A quiet group can be more active than it appears, while a public leak site can still give defenders only a partial view of the operation behind it.

Cynet vs. Doommageddon Ransomware

During simulated execution, Cynet’s unified cybersecurity platform was configured in detection mode, with prevention disabled, allowing Doommageddon to execute its complete attack flow so researchers could observe how the platform responded.

Cynet detected the ransomware through multiple layers:

  • AV/AI detection: The malicious binary was identified when it was written to disk or attempted to execute.
  • Threat intelligence: Third-party threat intelligence independently identified the malicious file.
  • Process monitoring: Cynet detected the vssadmin shadow-copy deletion based on the behavior of the launched process and command line.
  • Unauthorized memory access detection: The platform identified suspicious attempts to open handles into another process’s memory.
  • Ransomware protection: File-operation monitoring detected the abnormal .doomag extension and attempted writes against Cynet ransomware decoy files.

The encryptor is the loudest stage of the attack, but it is not necessarily the first opportunity to intervene. In this case, the lack of networking functionality inside the encryptor itself is strong evidence that exfiltration and other attacker activity occur separately. Defenders get multiple chances to detect the operation before the final impact stage.

We saw a related principle in our recent Settra ransomware investigation. Settra went much further than Doommageddon in protecting the ransomware itself, burying its encryptor inside an encrypted, password-gated payload. But once the malware began interacting with the system to encrypt data, behavioral protections still had an opportunity to identify and stop it.

What’s in a Name?

Doommageddon is not among the ransomware ecosystem’s biggest names. Cynet’s Doommageddon and DeadLock investigations both show how much activity can happen before a ransomware operation attracts meaningful public attention. Leak sites, victim counts, and splashy announcements are useful sources of threat intelligence, but they are lagging indicators.

For defenders, the best opportunity to disrupt ransomware remains before the ransom note appears: unusual access, privilege escalation, lateral movement, recovery inhibition, data staging, exfiltration, suspicious process behavior, and abnormal file operations. Waiting to identify the group behind an attack is not a luxury most security teams can afford.

Get the Full Report

This analysis is drawn from Cynet’s August 2026 Cyberthreat Intelligence Report overview, which also covers ShieldBreak, Maximum Overdrive, FadeSEC, the month’s high-severity CVE review, and broader ransomware activity. Cynet tracked 1,011 claimed ransomware victims across all groups during August alone.

For more CyOps ransomware research, see Inside Cynet’s Settra Ransomware Investigation, CyOps Analysis: Charon Ransomware, CyOps Analysis: Yurei Ransomware, and CyOps Analysis: BQTLock Ransomware

SUBSCRIBE

Briefings in your Inbox

Original CyOps research, monthly threat intel, and early access to webinars. No fluff. Unsubscribe anytime.

Related Posts

Inside Cynet’s Settra Ransomware Investigation 
Chaotic Eclipse Returns With Another Microsoft Defender Exploit
August 2026 Cyberthreat Intel Report: How a Small UK Power Plant Became a Very Public Warning
Unix Stealer Takes Aim at VPN Credentials and Crypto Wallets
DeadLock's Quiet Extortion Campaign

Reading is great. Seeing is better.

See Cynet's unified AI-powered platform in a 30-minute walkthrough tailored to your environment.

Search results for: