// THREAT ACTOR
LOLNEK_
DormantLOLNEK is a ransomware operator tracked through its public data-leak infrastructure. The group operates under the double-extortion model that defines the modern ransomware ecosystem — file encryption combined with the threat of stolen-data publication on a public leak site — and continues to post fresh victim claims as part of an ongoing extortion campaign.
For Ransomnews editorial coverage of LOLNEK — incident write-ups, attribution notes, and additional context — see the Threat Groups archive or run a site search.
Leak site mirrors
8 mirrors tracked, 0 currently reachable. These are criminal-infrastructure URLs — links are deliberately not provided.
-
mmeeiix2ejdwkmseycljetmpiwebdvgjts75c63camjofn2cjdoulzqd.onionsnapshot · 2022-08-27 14:02 -
obzuqvr5424kkc4unbq2p2i67ny3zngce3tbdr37nicjqesgqcgomfqd.onionsnapshot · 2023-05-11 06:03 -
nclen75pwlgebpxpsqhlcnxsmdvpyrr7ogz36ehhatfmkvakeyden6ad.onionsnapshot · 2022-10-01 00:05 -
mmcbkgua72og66w4jz3qcxkkhefax754pg6iknmtfujvkt2j65ffraad.onion404 Not Found snapshot · 2024-04-21 19:08 -
tzw7ckhurmxgcpajx6gy57dkrysl2sigfrt6nk4a3rvedfldigtor7ad.onionsnapshot · 2024-12-12 12:42 -
34vm2smykaqtzzzm4bgycfzg5fwyhhksrkpahdbiswmmuwuu7hmvuvqd.onionsnapshot · 2025-04-14 13:40 -
u2kqti2utfaiefucegnmd6yh6hledbsfanaehhnnn3q5usk6bvndahqd.onionsnapshot · 2025-04-14 13:40 -
mrv44idagzu47oktcipn6tlll6nzapi6pk3u7ehsucl4hpxon45dl4yd.onionsnapshot · 2025-04-14 13:41