DarkSide is a ransomware-as-a-service (RaaS) operation first publicly reported in August 2020 and widely known for the May 2021 Colonial Pipeline incident. The FBI confirmed DarkSide ransomware was responsible for the compromise of Colonial Pipeline networks. The intrusion was attributed to a DarkSide affiliate, and reporting in the provided content states initial access occurred via a legacy VPN account without MFA whose credentials had previously leaked or through an exposed reused VPN password. The attack affected Colonial Pipeline’s IT environment, including billing and accounting systems, led to a preventive shutdown of pipeline operations, and caused major fuel supply disruption on the U.S. East Coast. Colonial Pipeline paid 75 bitcoin, worth about $4.4 million at the time, and the U.S. Department of Justice later seized approximately $2.3 million in cryptocurrency tied to the payment.
DarkSide operated a structured affiliate program in which developers provided ransomware tooling, management panels, and leak-site capabilities in exchange for a share of ransom proceeds. The content states affiliates were interviewed before joining, developers took 25% of payments under $500,000 and 10% over $5 million, and affiliates could manage victims and choose what stolen data to publish. DarkSide used double extortion, stealing data before encryption and threatening public release if victims refused to pay. The operation was described as responsible for at least 60 known double-extortion cases in the referenced period, and its leak site reportedly featured stolen data from more than 80 companies in the U.S. and Europe.
Observed intrusion tradecraft in the provided content includes initial access via phished credentials, purchased or brute-forced VPN credentials, phishing, and exploitation of SonicWall SMA100 vulnerability CVE-2021-20016 by at least one affiliate cluster. Affiliates and related clusters used suspicious authentication attempts, spray-and-pray and brute-force activity, TeamViewer persistence, the Smokedham .NET backdoor, NGROK to expose remote desktop services, commodity malware such as SystemBC, and Cobalt Strike. Lateral movement methods mentioned include PSExec, RDP, and SSH. Sophos reported dwell times ranging from 44 to 88 days with a median of 45 days, while FireEye described some affiliate activity moving from access to ransomware deployment in as little as two to three days.
DarkSide targeted both Windows and Linux systems. The Windows variant appended a unique file extension to encrypted files, attempted privilege escalation via the CMSTPLUA technique when administrative privileges were absent, terminated services associated with Commvault, Veeam, MailEnable, and SQL Server, attempted to tamper with Sophos services, and deleted Volume Shadow Copies. The Linux variant was delivered as an ELF binary and specifically targeted VMware ESX/ESXi environments by encrypting VMDK virtual disk files, including under /vmfs/volumes/. The content also notes DarkSide was one of only a few ransomware families at the time reported to encrypt VMware ESXi shared virtual hard drives.
DarkSide publicly claimed to be apolitical and profit-motivated, and said it avoided certain public-interest sectors and companies in Russia, Kazakhstan, and Ukraine. However, the content also notes that its affiliate model limited central control over victim selection and attack consequences. Multiple references in the content associate DarkSide with Russian-speaking cybercrime ecosystems and actors, including affiliate recruitment of Russian-speaking partners, discussion on XSS, and claims by U.S. officials that the actors were believed to be in Russia, though the content states there was no confirmed nation-state link. The operation is described in the content as now defunct or retired.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Since initially surfacing in August 2020, the creators of DARKSIDE ransomware and their affiliates have launched a global crime spree affecting organizations in more than 15 countries and multiple industry verticals. | The threat actor obtained initial access to their victim by exploiting CVE-2021-20016, an exploit in the SonicWall SMA100 SSL VPN product, which has been patched by SonicWall. There is some evidence to suggest the threat actor may have used the vulnerability to disable multi-factor authentication options on the SonicWall VPN, although this has not been confirmed.
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In 2023, FIN7 expanded its operations to include the deployment of ransomware through affiliations with RaaS groups such as REvil and Maze, while also managing its own RaaS programs, including the now-retired Darkside and BlackMatter.
ELBRUS developed their own RaaS ecosystem named DarkSide. They deployed DarkSide payloads as part of their operations and recruited and managed affiliates that deployed the DarkSide ransomware.
FireEye researchers documented five separate clusters of activity suspected of being connected to DarkSide, the Ransomware-as-a-Service (RaaS) network responsible for the Colonial Pipeline security incident.
FireEye researchers documented five separate clusters of activity suspected of being connected to DarkSide, the Ransomware-as-a-Service (RaaS) network responsible for the Colonial Pipeline security incident.
FireEye researchers documented five separate clusters of activity suspected of being connected to DarkSide, the Ransomware-as-a-Service (RaaS) network responsible for the Colonial Pipeline security incident.
The attack began when a hacker group identified as DarkSide accessed the Colonial Pipeline network. The attackers stole 100 gigabytes of data within a two-hour window. Following the data theft, the attackers infected the Colonial Pipeline IT network with ransomware that affected many computer systems, including billing and accounting.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
In Sophos’ experience in data forensics and incident response to DarkSide attacks, the initial access to the target’s network came primarily as a result of phished credentials.
If it does not, the malware attempts to elevate its privileges using the CMSTPLUA technique.
In Sophos’ experience in data forensics and incident response to DarkSide attacks, the initial access to the target’s network came primarily as a result of phished credentials.
Like other ransomware, DarkSide also deletes Volume Shadow Copies, which could help recover some of the encrypted data if left unmolested.
Using PSExec, Remote Desktop connections, and (in the case of Linux servers) SSH to move laterally within the network...
Using PSExec, Remote Desktop connections, and (in the case of Linux servers) SSH to move laterally within the network...
Wazawaka seems to have adopted the uniquely communitarian view that when organizations being held for ransom decline to cooperate or pay up, any data stolen from the victim should be published on the Russian cybercrime forums for all to plunder.
...the company did pay as it sought to retrieve the stolen information.
DarkSide follows in the footsteps of double-extortion ransomware operators such as REvil, Maze, and LockBit—exfiltrating business data before encrypting it, and threatening public release if the victims don’t pay for a decryption key.
63 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
76 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware referenced as the malware used in the Colonial Pipeline incident, affecting IT billing systems rather than OT directly.
Ransomware family referenced as the operator behind the Colonial Pipeline attack; mentioned to explain why XSS.is banned overt ransomware-related forum activity.
A named ransomware operation/group referenced in connection with Telegram channels linked to exposed credential records.
DarkSide is referenced as the ransomware family inspiring the simulated attack scenario used to evaluate the defense agents.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.