Dark Project is a ransomware threat actor active by at least 2026 and associated with repeated public victim claims across multiple sectors. Reported operations indicate a data-theft-centric ransomware model in which victim environments are compromised and large volumes of sensitive corporate and personal information are exfiltrated, including financial records, employee and customer data, technical documentation, project drawings, and other internal business materials. Publicly attributed victim reporting for 2026 places Dark Project among the more active ransomware brands of that period, with 19 claimed victims in one observed week. Victims attributed to Dark Project include organizations in the United States, the United Kingdom, and the Philippines. Observed targeting spans automotive retail, manufacturing, transportation and logistics, staffing and recruiting, and utility-related services. Multiple incidents describe theft of substantial datasets measured in tens of gigabytes to multiple terabytes, indicating a strong exfiltration component and likely use of stolen data for extortion pressure. The available reporting supports ransomware activity and data exposure claims, but does not provide high-confidence detail on the group’s initial access methods, malware lineage, affiliate structure, or national sponsorship. Dark Project should be tracked as a financially motivated ransomware actor engaged in extortion against private-sector organizations, with demonstrated impact on manufacturing, industrial-adjacent businesses, transportation providers, and utility-related service firms. No corroborated source-country attribution is available from the supplied facts, and no additional aliases or sub-groups are established beyond the Dark Project name itself.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware group listed among the active groups for the week with claimed victims.
Conducting a ransomware attack and data theft against Long-Lewis Automotive Group, reportedly stealing more than 500 GB of confidential information and compromising over 650,000 files.
Conducting a ransomware attack involving data exfiltration against Mayco International; the leaked data reportedly includes internal documents, technical schemas, employee PII, and financial records.
Conducting a ransomware attack and associated data theft/extortion activity against Leviton, resulting in exfiltration of approximately 1.4 TB of sensitive data.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.