Skip to content

DarkAngels

DarkAngels is a Windows ransomware family assessed as a Babuk-derived or Babuk-rebranded variant and associated with targeted enterprise extortion.

Profile source: Mallory opens in a new tab

DarkAngels

Family profile

DarkAngels is a Windows ransomware family assessed as a Babuk-derived or Babuk-rebranded variant and associated with targeted enterprise extortion. It encrypts local files and can also encrypt content on network shares and mapped network paths. The malware enumerates services and running processes, terminates those that may interfere with encryption, deletes shadow copies to inhibit recovery, empties the recycle bin, gathers basic system information, and uses multithreaded encryption based on available processors. It drops a ransom note and appends a new extension to encrypted files. Its behavior and code artifacts show strong overlap with Babuk, including exclusion logic and a characteristic marker appended to encrypted data. DarkAngels has been described as being used in selective attacks against specific organizations rather than broad opportunistic deployment. Extortion messaging indicates double-extortion behavior, threatening public disclosure of stolen data and notification of external parties if victims do not engage within a short deadline. Reporting has also linked DarkAngels to use of Ragnar Locker's original ESXi encryptor in at least one observed case, suggesting code sharing, operational overlap, or tooling reuse within the ransomware ecosystem.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Extortion
  • Lateral Movement
  • Reconnaissance

Operational record

1
YARA rules
2
Ransom notes
1
Leak sites
0 available

MITRE ATT&CK

DarkAngels in ATT&CK

10 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.