ZeroHour

d1r

ransomware group · aka d1r · unknown (no public attribution reporting) · active since 2026-07-12 (first leak-site post tracked by this dashboard); earlier activity, if any, unknown

Victims · 7d
0flat
Victims · 30d
0active targets
Victims · 90d
3
All-time (tracked)
3since 2026-07-12
Last post
07-12 16:02UTC
Estimated earnings
public reporting
Profile · glm-5.3-flash · updated

Estimated earnings

No public figure.

Leak-site victims

VictimDiscoveredDetails
Bosch · Jul 12, 2026Again, thanks to database Synopsys provided us with After analyzing technical leaks by other groups and cross-referencing targets from TARGETLIST.txt A company access was found and in the archives, a $10,000 gem: Bosch CAN module implementation Now it is going for free for every engineer and car enthusiast, thanks to Synopsys providing us with neat roadmap to tech sector Sorry, Bosch, you got third-partied! Call the Synopsys CEO and thank them for letting us all know where the valuable data is!
ARM · Jul 12, 2026Thanks to leaked database by Synopsys, a roadmap was provided Many other group leaks were cross-referenced and thoroughly analyzed One of the leaked companies gave our team access to ARM center Severely incapacitated by 2FA email/sms-code required by ARM on every step, we were still able to download an interesting tool: Athena Download Manager That requires an SSL certificate of a company that owns ARM products, and downloading by means of Athena allows to bypass multiple 2FA checks that are required when downloading same files from www.arm.com This is now free for download to any reverse engineer on Earth and beyond, thanks to Synopsys company data negligence:
Synopsys · Jul 12, 2026

In the newsAll →

No articles mention this group yet.

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .