DarkSide is a ransomware-as-a-service (RaaS) operation known for the May 2021 Colonial Pipeline attack, which the FBI attributed to the group and which was carried out by a DarkSide affiliate. The intrusion reportedly used a legacy VPN account without MFA whose credentials had previously leaked. The incident led Colonial Pipeline to shut down operations, causing major fuel supply disruption on the U.S. East Coast. U.S. authorities later seized approximately $2.3 million in cryptocurrency tied to the ransom payment. Content describes DarkSide as a Russia-based or Russian-speaking cybercriminal group, while also noting public statements that it was apolitical and financially motivated rather than state-directed. The group operated an affiliate-based RaaS model in which developers provided ransomware tooling, management panels, and leak-site capabilities in exchange for a share of ransom proceeds. DarkSide was associated with at least 60 known double-extortion cases in the referenced period and used data theft prior to encryption to pressure victims with public release. Reported affiliate revenue-sharing terms included 25% of payments under $500,000 and 10% over $5 million, and prospective affiliates were interviewed before joining. Reported tradecraft includes initial access via phished or stolen credentials, including VPN access; use of commodity malware such as SystemBC and tools including Cobalt Strike; lateral movement via PSExec, RDP, and SSH; exfiltration to Mega or pCloud; and dwell times observed by Sophos ranging from 44 to 88 days with a median of 45 days. FireEye linked multiple affiliate clusters to the ecosystem, including UNC2628, UNC2659, and UNC2465. Reported techniques included brute-force and credential-based VPN access, exploitation of SonicWall SMA100 vulnerability CVE-2021-20016, TeamViewer persistence, phishing, use of the Smokedham .NET backdoor, and NGROK to expose remote desktop services. The Windows variant reportedly appended a unique file extension, attempted privilege escalation via CMSTPLUA when needed, terminated backup and database-related services including Commvault, Veeam, MailEnable, and SQL Server, tampered with Sophos services, and deleted Volume Shadow Copies. A Linux variant was delivered as an ELF binary and targeted VMware ESX environments by encrypting VMDK files under /vmfs/volumes/. DarkSide publicly claimed to avoid certain sectors tied to the public interest and later said it would moderate target selection after the Colonial Pipeline incident, but the content notes that the affiliate model limited operator control over victim selection and consequences. The group is also referenced in reporting that BlackMatter and later BlackCat/ALPHV were rebrands or successor operations following law-enforcement pressure after Colonial Pipeline. DarkSide is additionally associated in the content with use of SystemBC, and affiliate reporting links Mikhail Matveev (Wazawaka) to DarkSide-related activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
44 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
18 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as the ransomware group behind the Colonial Pipeline incident, used here as an example of OT/IT risk assessment gaps rather than the main subject.
Referenced as the ransomware group whose Colonial Pipeline attack prompted XSS to ban overt ransomware-related forum activity.
Referenced as the ransomware group associated with the Colonial Pipeline attack; the content notes Telegram channels bearing its name were among sources contributing exposed credential records.
Referenced as a benchmark for high-quality ESXi ransomware locker development.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.