DarkSide was a Russian-speaking ransomware-as-a-service operation active in the early 2020s and best known for the 2021 attack on Colonial Pipeline. The group operated an affiliate model in which core developers supplied ransomware tooling, management infrastructure, and leak-site capabilities to partners who conducted intrusions and shared ransom proceeds. DarkSide publicly portrayed itself as financially motivated and apolitical, while claiming to avoid certain sectors and post-Soviet targets, but its affiliate structure limited centralized control over victim selection and attack consequences. DarkSide used double extortion, stealing data before encrypting systems and threatening public release to pressure victims into payment. Reported intrusions commonly began with compromised credentials, including phishing-derived access and VPN account abuse, and in some cases involved brute-force activity or exploitation of remote access infrastructure. Observed post-compromise behavior included long dwell times, reconnaissance, lateral movement via remote administration protocols and administrative tooling, privilege escalation, data exfiltration to cloud storage services, service termination to facilitate encryption, deletion of shadow copies, and attempts to tamper with security products. DarkSide deployed ransomware against both Windows and Linux environments, including virtualization infrastructure. The operation has been associated with use of commodity and post-exploitation tooling such as Cobalt Strike and SystemBC. Multiple affiliate clusters linked to the ecosystem used varied intrusion tradecraft, including credential attacks, phishing, persistence through remote management software, and broader hands-on-keyboard post-exploitation. DarkSide was responsible for numerous double-extortion incidents and had a significant impact on critical infrastructure through the Colonial Pipeline event, which disrupted fuel distribution in the eastern United States. Following intense law-enforcement and political pressure after that incident, DarkSide ceased public operations; the broader operator ecosystem has been widely linked to subsequent rebrands including BlackMatter and later ALPHV/BlackCat.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
44 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
18 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware group responsible for the Colonial Pipeline incident, demonstrating disruptive impact on critical infrastructure.
Referenced as the ransomware group behind the Colonial Pipeline incident, used here as an example of OT/IT risk assessment gaps rather than the main subject.
Referenced as the ransomware group whose Colonial Pipeline attack prompted XSS to ban overt ransomware-related forum activity.
Referenced as the ransomware group associated with the Colonial Pipeline attack; the content notes Telegram channels bearing its name were among sources contributing exposed credential records.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.