The DarkSide ransomware operation said it was building a distributed storage platform in Iran to host and publish data stolen from victims, a move intended to make law-enforcement disruption and infrastructure takedowns more difficult. The group described itself as a private ransomware-as-a-service operation in which core developers supply the malware and payment systems while affiliates breach targets and split ransom proceeds.
DarkSide also used a Russian-speaking cybercrime forum to recruit affiliates, claiming participants earn about $400,000 per victim on average, and posted a 20 BTC deposit—worth roughly $320,000 at the time—to signal financial credibility. The gang said it would avoid attacks on healthcare, education, non-profits, and government entities, but the report noted it was unclear whether those restrictions would be enforced in practice.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
The article states that ransomware groups have widely used double extortion since late 2019, stealing unencrypted data before encrypting victim systems and threatening to publish it to pressure victims into paying.
To demonstrate financial credibility to prospective affiliates, DarkSide deposited 20 bitcoins on the hacker forum, worth about $320,000 at the time according to the article.
DarkSide posted on a Russian-speaking hacker forum that it was recruiting new Russian affiliates and building a distributed storage system in Iran or unrecognized republics to host stolen victim data and resist takedowns.
The article references a September recruitment drive by REvil in which the group deposited $1 million in bitcoins on the same Russian-speaking hacker forum as a credibility signal.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.