Dark Project is a ransomware threat actor associated with data-theft incidents against organizations in multiple sectors. Reported victims include manufacturing firms, a transportation and logistics company, an energy and utilities service provider, and a staffing and recruiting business serving engineering, information technology, health care, and industrial customers. Observed victim geography includes the United States, the Philippines, and the United Kingdom. Reported intrusions involved ransomware activity accompanied by substantial exfiltration of sensitive corporate and personal data, including financial records, employee information, customer information, technical schematics, project drawings, and other internal business documents. The available reporting supports Dark Project’s use of extortion-oriented ransomware operations with a strong emphasis on stealing data from victim environments. No high-confidence attribution to a specific country of origin or state sponsor is currently available from the supplied facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a ransomware attack involving data exfiltration against Mayco International; the leaked data reportedly includes internal documents, technical schemas, employee PII, and financial records.
Conducting a ransomware attack and associated data theft/extortion activity against Leviton, resulting in exfiltration of approximately 1.4 TB of sensitive data.
Conducting a ransomware attack and data theft against Brainhunter Companies LLC. and Brainhunter Systems Ltd., with more than 160 GB of confidential data reportedly stolen.
Conducting a ransomware attack and associated data breach against The Miller Group, resulting in loss of control over 500 GB of confidential data.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.