Skip to content
Ransomware group

D1R

D1R is a newly identified ransomware and extortion actor that emerged publicly in 2026.

Profile source: Mallory opens in a new tab

D1R

Family profile

D1R is a newly identified ransomware and extortion actor that emerged publicly in 2026. The group is associated with a leak site used to name victims and pressure them with threatened publication of allegedly stolen data. Reported victim claims linked to D1R include Synopsys, Bosch, and Arm, although important elements of those claims remain disputed or unverified.

D1R has portrayed itself as capable of exploiting weaknesses in externally exposed web applications and then using obtained corporate or customer information to pursue follow-on targeting against downstream organizations. In public claims, the group alleged that it exploited a logic flaw in a Synopsys registration workflow to obtain a large corporate client database and then leveraged that information to identify or access Bosch- and Arm-related material. The actor has also claimed theft of engineering and hardware-development information, indicating an interest in high-value intellectual property in addition to conventional ransomware extortion.

The group’s observed tradecraft is consistent with modern multi-extortion operations: public victim shaming on a Tor-based leak site, deadlines for contact, threats to publish data, and use of screenshots or sample files to support coercion. Its claimed targeting suggests a focus on technology, semiconductor, manufacturing, and engineering ecosystems, including supply-chain relationships where compromise of one organization may be leveraged to pressure or target another.

Attribution beyond its self-identified name is currently not available. No confirmed nation-state affiliation is established. Confidence in D1R’s operational claims should be treated cautiously: Synopsys publicly stated that it found no evidence supporting the alleged breach or unauthorized access to customer technical data, and some purported proof material was assessed as potentially publicly available. As a result, D1R is best characterized at present as an emerging ransomware extortion brand whose public claims have outpaced independent verification. No widely recognized aliases or confirmed sub-groups are currently established beyond the name D1R.

Ransomware.live

Operational record

View group record ↗

Ransomware.live

Recent claims

All published claims ↗

MITRE ATT&CK

D1R in ATT&CK

12 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.