RANSOMWARE OPERATION💰 FINANCIAL

D1R

Intelligence Profile

D1R Claims Synopsys and Bosch Breaches, but Synopsys Disputes Intrusion

Intelligence Assessment

D1R is a ransomware operation driven by financial motivations. The group has claimed responsibility for high-profile breaches, though some claims have been disputed by the targeted organizations.

The group has tracked 3 victims in the last 90 days across the technology and manufacturing sectors in Germany, the United Kingdom, and the United States.

Outlook

The actor is currently active, with its most recent recorded attack occurring on 2026-07-12.

Generated by the CTIWATCH analysis pipeline from this actor's tracked data (victims, campaigns, TTPs, activity). Attribution and assessments may be incomplete — verify against primary reporting before acting.

Threat Analysis

D1R is a ransomware operation that deploys encryption-based extortion against organizations globally. This group maintains a data leak site (DLS) to pressure victims into paying ransom demands.

Financially motivated threat actors like D1R prioritize monetary gain through methods such as ransomware deployment, banking trojans, cryptocurrency theft, BEC scams, or credential harvesting for resale on underground markets.

Ransomware Victims (3)

CTIWATCH tracks 3 organizations claimed as victims by D1R on its data leak site, with attack dates, sectors and countries.

View full victims list →

Intelligence Reports Mentioning D1R

Quick Facts

TypeRansomware Operation
Motivation💰 financial

Research Links

Data sourced from Malpedia, Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Actor attribution is based on available intelligence and may be incomplete.