Dark Project is a ransomware threat group associated with attacks against organizations in the United States, Brazil, and the Philippines. Its reported victimology includes manufacturers, engineering and construction-related firms, healthcare providers, professional-services organizations, logistics providers, hospitality businesses, automotive retailers, and utility-related service providers. Operations have reportedly combined theft of large volumes of sensitive corporate, financial, customer, employee, and technical data with encryption of victim systems, consistent with double-extortion ransomware activity. Exfiltrated material has included personally identifiable information, financial and banking records, customer databases, technical schematics, project drawings, and architectural plans. The group has been linked to a sustained volume of ransomware claims during 2026. Dark Project is also known as dark_project.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducted a ransomware attack against Specchem LLC, reportedly stealing approximately 500 GB of data comprising roughly 700,000 files, including confidential personal and financial information.
Conducted a ransomware attack against MEI Architects and allegedly stole approximately 340 GB of data, including identity documents, HR records, invoices, and architectural drawings.
Allegedly conducted a ransomware and data-theft attack against Alurwalls, a Brazilian manufacturer of glass-wall systems.
Conducted a ransomware attack against Master Manufacturing Co., Inc. in the United States and reportedly exfiltrated 36 GB of data, including SQL databases containing personal data and technical plans and schematics for custom metal parts.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.