Doommageddon is a ransomware group that emerged in July 2026, utilizing a double-extortion model that combines file encryption and data exfiltration. The group targets various sectors, leveraging sophisticated tactics such as social engineering and advanced malware to maximize financial gain from its victims.
Key insights
•Utilizes RSA-2048 asymmetric encryption to append the .doomag extension to files.
•Employs social engineering phishing campaigns and exploits network vulnerabilities for initial access.
•Implements a structured Tor-based data leak site categorizing victim negotiation statuses.
•Enforces double extortion by publicly threatening to release sensitive data if ransoms are not paid.
•Communicates with victims through the Session messaging application for direct ransom negotiations.