Mandiant reported that DARKSIDE operated as a ransomware-as-a-service group that combined data theft and file encryption, with affiliates conducting intrusions that moved from initial access to hands-on-keyboard post-exploitation before deploying ransomware. The group’s operations were associated with common enterprise attack tooling and tradecraft designed to blend into Windows environments, helping operators maintain access, move laterally, and prepare victim networks for extortion.
The referenced techniques and detections show how that activity can appear on endpoints: adversaries may abuse trusted Microsoft utilities Regsvcs and Regasm under MITRE ATT&CK T1218.009 to proxy malicious .NET code execution and evade application controls, while post-compromise activity may also surface through Cobalt Strike named pipes tied to Beacon, Artifact Kit, and Malleable C2 profiles. Splunk previously published analytics based on Sysmon Event IDs 17 and 18 to identify those pipe patterns, underscoring how defenders can spot the command-and-control and lateral movement behavior often seen in ransomware intrusions linked to groups such as DARKSIDE.

TTPs, infrastructure, and targeting history in one profile.
15 events from the most recent confirmed update back to the earliest known activity.
Splunk Threat Research removed the "Cobalt Strike Named Pipes" analytic from its content library and stated it is no longer maintained or supported. Splunk said the detection was consolidated into the broader "Windows Suspicious C2 Named Pipe" detection.
Acronis published technical analysis stating DarkSide was being delivered through the Zloader botnet, compromised third-party service providers, exploitation of Palo Alto CVE-2019-1579, and exposed Microsoft Exchange vulnerabilities. The report also documented sample behavior, encryption methods, embedded affiliate configuration, and command-and-control domains.
FortiGuard Labs published analysis of a DarkSide variant with uncommon capabilities to enumerate and mount additional disk partitions in multi-boot environments, discover domain controllers via anonymous LDAP, and encrypt files on writable network shares while skipping administrative shares. The report also documented related incident-response findings including Cobalt Strike SMB/HTTPS beacons, Rclone-based exfiltration, WMI shadow copy deletion, PsExec and rundll32 execution, persistence via a created service, and C2 infrastructure tied to 185.180.197[.]86 and tailgatethenation.com.
Splunk Threat Research published a DarkSide ransomware threat update after replicating the payload in a test environment. The post released a DarkSide analytic story and detections for behaviors including ransom note creation, shadow copy deletion via PowerShell, and CMSTPLUA/CMLUA UAC bypass activity.
Mandiant published "Shining a Light on DARKSIDE Ransomware Operations," documenting DARKSIDE ransomware activity. The report is one of the references tied to later Splunk detection content associated with DarkSide ransomware.
A ransomware attack attributed to DarkSide targeted Colonial Pipeline in the United States, prompting the company to proactively shut down the pipeline on Sunday, May 9. The outage raised concerns about fuel prices and how long the disruption would last.
GhouLSec published a technical reverse-engineering analysis of DarkSide ransomware, detailing its execution flow, privilege-escalation methods, persistence, service-killing logic, victim profiling, and encryption design. The post also identified the sample hash afb22b1ff281c085b60052831ead0a0ed300fac0160f87851dacc67d4e158178 and reported attempted communication with securebestapp20[.]com using a generated URL path.
DarkSide announced that it had invaded multiple companies listed on Nasdaq and other stock exchanges, claiming it encrypted core data and threatening to publish stolen information and profit through short-selling if victims refused to pay.
Cobalt Strike published a blog post, "Learn Pipe Fitting for all of your Offense Projects," describing named pipe usage relevant to offense projects. This material is later referenced by Splunk as context for named pipe patterns associated with Cobalt Strike.
MIT Technology Review reported that New Orleans law firm Stone Pigman Walther Wittmann was among the victims listed by DarkSide. The article says the DarkSide attack on the firm occurred in February, and firm representatives said it did not pay the ransom.
Bitdefender Labs published a DarkSide ransomware decryption tool. This represents a new defensive development aimed at helping victims recover encrypted files without paying the ransom.
On 2020-10-11, a user advertised the DarkSide ransomware affiliate program on a Russian-speaking darkweb forum. The post promoted targeting large corporations and said affiliates would receive access to Windows and Linux variants, an admin panel, a leak site, and supporting infrastructure.
DarkSide publicly introduced itself as a ransomware-as-a-service operation. The group presented itself as a big-game hunter with targeting rules and an affiliate-driven business model.
DarkSide began targeted attacks against organizations around August 10, 2020, using customized ransomware builds and double-extortion tactics. The report said observed demands ranged from about $200,000 to $2 million and that at least one victim had already paid more than $1 million.
Elliptic published an analysis stating that DarkSide had netted more than $90 million in bitcoin ransom payments. The report added a financial assessment of the ransomware operation's proceeds that was not reflected in the existing timeline.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 134 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
24 references tracked. Mallory keeps watching after this page renders.
research.splunk.com
Open sourcegithub.com
Open sourcevaronis.com
Open sourcelabs.bitdefender.com
Open sourcewikileaks.org
Open sourceattack.mitre.org
Open sourceattack.mitre.org
Open sourceelliptic.co
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.