DarkSide is a human-operated ransomware family and ransomware-as-a-service operation active from approximately August 2020 until May 2021. Affiliates conducted intrusions and deployed configurable encryptors against large private-sector organizations, while the core operation supplied ransomware and extortion infrastructure. DarkSide used double extortion: it encrypted victim data, exfiltrated sensitive information, and threatened public disclosure through a leak site if payment was not made. The ransomware targeted Windows and Linux systems, including Linux environments used to affect virtualized enterprise infrastructure. DarkSide sought access to large U.S. businesses through initial-access brokers and reportedly avoided systems configured for Commonwealth of Independent States countries. It was responsible for the May 2021 Colonial Pipeline attack, which caused an operational shutdown and fuel-supply disruption in the United States. BlackMatter was widely assessed as a successor or rebrand of DarkSide, and subsequent reporting has identified technical and operational lineage connecting DarkSide, BlackMatter, and BlackCat/ALPHV.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In others, the CVE-2019-1579 vulnerability in Palo Alto’s GlobalProtect portal and GlobalProtect Gateway interface products and Microsoft Exchange server exposure were used. As a result of exploitation, an unauthenticated attacker could execute malicious code remotely (RCE). | DarkSide ransomware recently attacked the Colonial Pipeline — the largest pipeline in the United States... DarkSide stands out from other ransomware as a service (RaaS) threats, as one of the attack vectors is based on the Zloader botnet (also known as “Silent Night”).
Since initially surfacing in August 2020, the creators of DARKSIDE ransomware and their affiliates have launched a global crime spree affecting organizations in more than 15 countries and multiple industry verticals. | The threat actor obtained initial access to their victim by exploiting CVE-2021-20016, an exploit in the SonicWall SMA100 SSL VPN product, which has been patched by SonicWall. There is some evidence to suggest the threat actor may have used the vulnerability to disable multi-factor authentication options on the SonicWall VPN, although this has not been confirmed.
9 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
FIN7 has attempted to run Darkside ransomware with the filename sleep.exe.
SMOKEDHAM ... a été utilisée par UNC24655, un affilié RaaS précédemment associé aux groupes Lockbit et Darkside.
On Sunday, May 9th Dragos released an intel report to our customers that assessed with high confidence that the DarkSide ransomware group was responsible for the IT compromise.
BlackMatter is linked to the Coreid cyber crime group, which was previously responsible for the Darkside ransomware.
ELBRUS developed their own RaaS ecosystem named DarkSide. They deployed DarkSide payloads as part of their operations and recruited and managed affiliates that deployed the DarkSide ransomware.
FireEye researchers documented five separate clusters of activity suspected of being connected to DarkSide, the Ransomware-as-a-Service (RaaS) network responsible for the Colonial Pipeline security incident.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
operators have gained entry through insecure remote access services using compromised credentials.
Stealth tactics include: ... Obfuscation techniques like encoding and dynamic library loading
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
operators have gained entry through insecure remote access services using compromised credentials.
Once inside the network, attackers used known techniques for increasing access and compromising the network, including Living-off-the-Land Binaries (LOLbins) and offensive security tools such as Cobalt Strike, Mimikatz and others.
The malware creates a mutex called “Global\4787658f1cc4202b8a15e05dd0323fde”, which makes sure that there is only one instance of the ransomware running at a time.
By targeting virtual machines, ransomware operators can also encrypt multiple servers at once with a single command. In June, researchers spotted a new REvil ransomware Linux encryptor designed to target VMware ESXi virtual machines, a popular enterprise virtual machine platform.
They emphasized their speed of encryption and a wealth of options for dealing with anything that may inhibit the encryption process (i.e., security software). ... process termination, service termination
Researchers said the malware “parses its embedded configuration, kills virtual machines, encrypts files on the infected machine, collects system information, and sends it to the remote server.”
For this phase, DarkSide abuses various tools, namely PowerShell, Metasploit Framework, Mimikatz, and BloodHound... DarkSide aims to gain Domain Controller or Active Directory access.
By targeting virtual machines, ransomware operators can also encrypt multiple servers at once with a single command. In June, researchers spotted a new REvil ransomware Linux encryptor designed to target VMware ESXi virtual machines, a popular enterprise virtual machine platform.
This ransomware group follows the double extortion tactic – meaning not only do they encrypt the user’s data, but also exfiltrate it and threaten to make it public in case the ransom demand is not met.
This ransomware group follows the double extortion tactic – meaning not only do they encrypt the user’s data, but also exfiltrate it and threaten to make it public in case the ransom demand is not met.
The latest version of DarkSide attempts to stop the same list of backup and anti-malware services as previous versions targeted | DarkSide kills processes that contain the following strings in their names to unlock the files
The binary uses COM objects and WMI commands to delete volume shadow copies... it deletes each of the shadow copy objects via the DeleteInstance method. | Offset 0x06 Yes Delete volume shadow copies... The process executes the following SQL query “SELECT * FROM Win32_ShadowCopy” ... and then it deletes each of the shadow copy objects via the DeleteInstance method.
146 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
DarkSide is mentioned only as background comparison for how other ransomware operations faced disruption after high-profile attacks.
Ransomware referenced as a former REvil affiliate involved in the Colonial Pipeline attack; mentioned for background and comparison rather than as the main malware in this reference.
Ransomware operated via an affiliate model. The operators provide crypto-locking malware to affiliates, maintain payment and leak-site infrastructure, target large organizations, can encrypt both Windows and Linux files, and use data theft plus public shaming to pressure victims into paying.
Ransomware family described here as the predecessor/continuation lineage for BlackMatter; the first BlackMatter version was said to be almost identical to the latest DarkSide version.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.