Blockchain analysis linked DarkSide to at least $90 million in bitcoin ransom payments over roughly nine months, tracing funds across 47 wallets tied to the ransomware-as-a-service operation. Two of the group’s most prominent victims accounted for about $10 million of that total: Colonial Pipeline, which paid nearly $5 million, and chemical distributor Brenntag, which paid $4.4 million. The gang’s affiliate model reportedly gave partners 75% to 90% of each payment, while the core operators retained a smaller share that still amounted to about $15.5 million in bitcoin.
DarkSide’s campaign also involved data theft as well as encryption. Brenntag said attackers accessed its North America systems in late April 2021, exfiltrating sensitive personal data affecting more than 6,700 individuals, including Social Security numbers, dates of birth, driver’s license numbers, and some medical information; the company said DarkSide claimed to have stolen 150GB of data and that access may have been obtained through purchased stolen credentials. After the Colonial Pipeline attack drew intense scrutiny, DarkSide said it lost control of parts of its infrastructure and some ransom funds before abandoning operations, while major cybercrime forums including XSS, Exploit, and RAID banned ransomware advertisements and other gangs shifted toward private affiliate arrangements rather than disappearing entirely.

TTPs, infrastructure, and targeting history in one profile.
13 events from the most recent confirmed update back to the earliest known activity.
In late June 2021, Brenntag sent breach notification letters to more than 6,700 affected individuals after determining personal data had been exfiltrated.
After DarkSide's reported shutdown, REvil told affiliates they must obtain approval before targeting organizations and barred attacks on healthcare, education, and government entities. The change was presented as a response to increased pressure following the Colonial Pipeline incident and DarkSide disruption.
Elliptic published analysis showing DarkSide had collected at least $90 million in roughly nine months and that its developers received about $15.5 million of that total.
President Biden delivered public remarks on the Colonial Pipeline incident, providing an official U.S. government response as scrutiny intensified around ransomware and DarkSide. The statement came the same day DarkSide said it was shutting down operations.
DarkSide's operations closed on May 13, 2021 after fallout from the Colonial Pipeline incident; the group said it had lost control of some servers and some ransom funds.
Brenntag sent DarkSide a $4.4 million ransom payment on May 11, 2021 to obtain a decryptor and prevent publication of stolen data.
Brenntag became aware of the attack on April 28, 2021 and disconnected impacted systems from its network after discovering the incident.
Brenntag said attackers linked to DarkSide began unauthorized access to its North America systems on April 26, 2021.
Elliptic identified DarkSide ransom transactions totaling just over $90 million since October 2020 across 47 Bitcoin wallets, establishing the scale of the group's earnings.
DarkSide began operating as a ransomware-as-a-service group in August 2020, using affiliates to breach victims, steal data, and deploy encrypting malware.
The Record reported that smaller ransomware groups Ako (Razny) and Everest appeared to shut down over the weekend amid pressure on the ransomware ecosystem.
After DarkSide disappeared, REvil and Avaddon announced they would stop advertising on forums and continue operating privately with existing affiliates and recommendations.
Following the Colonial Pipeline fallout, the XSS, Exploit, and RAID forums banned ransomware advertisements, signaling a shift in how ransomware groups could recruit and operate publicly.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
7 references tracked. Mallory keeps watching after this page renders.
bleepingcomputer.com
Open sourcebleepingcomputer.com
Open sourcetherecord.media
Open sourceelliptic.co
Open sourcetherecord.media
Open sourcebleepingcomputer.com
Open sourcewhitehouse.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.