Skip to content

Doommageddon

Doommageddon is a ransomware and data-extortion threat actor active by mid-2026.

Profile source: Mallory opens in a new tab

Doommageddon

Family profile

Doommageddon is a ransomware and data-extortion threat actor active by mid-2026. Publicly attributed activity links the group to attacks and leak claims against organizations in Brazil, Paraguay, and the United States, with observed victims spanning healthcare, financial services, business services, and consumer services. The actor appears to operate a leak-and-pressure model in which victims are named publicly, deadlines are set, and incident status may progress through stages such as upcoming, leaked, or negotiated.

Observed behavior indicates a strong emphasis on extortion through threatened or actual publication of stolen data. In at least one healthcare-related case, the actor claimed a staged, multi-wave release strategy, beginning with limited medical data and threatening broader disclosure of protected health information, personal data, and full databases if demands were not met. This pattern is consistent with double-extortion tradecraft centered on reputational pressure and coercive disclosure timelines.

Known targeting includes healthcare organizations and other enterprises in Latin America, particularly Brazil, as well as additional victims in Paraguay and the United States. The available information supports classifying Doommageddon as a ransomware-associated cybercriminal actor. No high-confidence public evidence in the available material establishes a nation-state affiliation, formal sub-groups, or additional widely used aliases beyond the name Doommageddon itself.

Operational record

Recent claims

MITRE ATT&CK

Doommageddon in ATT&CK

3 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.