DarkAngels is a Windows ransomware family assessed as a Babuk-derived or Babuk-rebranded variant and associated with targeted enterprise extortion. It encrypts local files and can also encrypt content on network shares and mapped network paths. The malware enumerates services and running processes, terminates those that may interfere with encryption, deletes shadow copies to inhibit recovery, empties the recycle bin, gathers basic system information, and uses multithreaded encryption based on available processors. It drops a ransom note and appends a new extension to encrypted files. Its behavior and code artifacts show strong overlap with Babuk, including exclusion logic and a characteristic marker appended to encrypted data. DarkAngels has been described as being used in selective attacks against specific organizations rather than broad opportunistic deployment. Extortion messaging indicates double-extortion behavior, threatening public disclosure of stolen data and notification of external parties if victims do not engage within a short deadline. Reporting has also linked DarkAngels to use of Ragnar Locker's original ESXi encryptor in at least one observed case, suggesting code sharing, operational overlap, or tooling reuse within the ransomware ecosystem.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
If the given command-line argument is 'paths,' then the ransomware calls GetDriveTypeW() API to find out the network drive connected to the infected machine.
The ransomware also enumerates the running processes using CreateToolhelp32Snapshot(), Process32FirstW(), and Process32NextW() APIs, checks the process names such as sql.exe,oracle.exe, powerpnt.exe, etc., and terminates them if they are actively running.
After dropping the ransom notes, the malware encrypts the files on the victim’s machine and appends the extension with '.crypt.'
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named malware/tool family listed as detectable via favicon hash hunting of exposed infrastructure.
Listed as a malware/tool name in a collection of SHA-256 hashes intended to help identify C2 infrastructure, open directories, and phishing assets.
Ransomware operation reported to have used Ragnar Locker’s original ESXi encryptor in an attack; relationship to Ragnar Locker (offshoot/rebrand/source-code purchase) is unclear.
Targeted ransomware that terminates services/processes (e.g., VSS/SQL-related), deletes shadow copies via vssadmin.exe, empties the recycle bin, enumerates local drives and network shares/paths, encrypts files, drops a ransom note (How_To_Restore_Your_Files.txt), and appends the extension ".crypt" to encrypted files.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.