DarkSide was a financially motivated, human-operated ransomware-as-a-service (RaaS) operation active from 2020 through its shutdown following the May 2021 Colonial Pipeline incident. It conducted big-game ransomware attacks against large private-sector organizations, including U.S. businesses, and recruited affiliates and initial-access brokers through Russian-language cybercrime forums. Affiliates received customized ransomware payloads and a substantial share of ransom payments, while the core operation supplied malware, payment and negotiation infrastructure, and a public leak site. DarkSide used double extortion: affiliates stole data, encrypted victim systems, and threatened public release of stolen material if payment was withheld. The operation supported Windows and Linux encryption, including targeting of Linux and ESXi environments. It maintained a victim leak site and, in some cases, employed expanded extortion pressure through DDoS activity and direct contact with victims’ customers. DarkSide’s operators claimed to exclude certain sectors and systems in Commonwealth of Independent States countries, but these stated restrictions did not prevent a disruptive attack on Colonial Pipeline. The Colonial Pipeline attack caused an operational shutdown and fuel-supply disruption in the United States. Following the incident, DarkSide reported losing access to infrastructure and ransom funds and ceased public operations. BlackMatter was subsequently assessed as a continuation or repaint of DarkSide based on near-identical ransomware code and operational continuity; later BlackCat/ALPHV activity was also widely assessed as succeeding the DarkSide and BlackMatter ecosystem.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
48 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
77 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as another ransomware operation that faced pressure after the Colonial Pipeline attack.
Operating a ransomware affiliate program, recruiting affiliates and initial access brokers, running a leak site for extortion, and targeting large organizations for big-game ransomware attacks.
Referenced as the predecessor/continuation lineage for BlackMatter; BlackMatter is described as nearly identical to the latest DarkSide version in its earliest iteration.
Mentioned as a comparison and in discussion of possible operational similarities with BlackCat.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.