Skip to content

DarkBit

DarkBit is a Windows ransomware family and destructive attack persona associated with Iranian state-linked operations, particularly activity attributed to DEV-1084 and linked by multiple reports to MuddyWater, also tracked by Microsoft as Mango Sandstorm.

Profile source: Mallory opens in a new tab

DarkBit

Family profile

DarkBit is a Windows ransomware family and destructive attack persona associated with Iranian state-linked operations, particularly activity attributed to DEV-1084 and linked by multiple reports to MuddyWater, also tracked by Microsoft as Mango Sandstorm. It became publicly known in 2023 during the attack on the Technion Israel Institute of Technology, where the operation was widely assessed as politically motivated and disruptive rather than a conventional profit-driven ransomware campaign. DarkBit has also been described as a front or persona used to mask destructive activity under the appearance of ransomware.

Technically, DarkBit is a 64-bit Windows executable written in Go and protected with obfuscation, including concealed DLL and API names and dynamic API resolution to hinder static analysis and detection. Observed behavior includes mutex-based single-instance control, multithreaded execution, filesystem traversal to identify files for encryption, chunked file processing, appending encrypted key material to affected files, renaming encrypted files with a dedicated extension, and dropping ransom notes in impacted directories. The malware has been observed deleting shadow copies prior to encryption and contains logic consistent with using Windows Restart Manager APIs to handle locked files. Analysis of available samples indicates use of strong symmetric file encryption, while later research showed implementation weaknesses in key generation that enabled development of a decryptor.

Reported intrusion chains tied to DarkBit involved a lure delivered in an ISO image containing a disguised shortcut and archive. The shortcut abused a legitimate Windows utility to unpack and launch a payload identified as a Cobalt Strike beacon, which then retrieved the ransomware stage. This supports assessment that DarkBit was deployed after an initial foothold and post-compromise staging rather than as a simple commodity ransomware drop. The ransom messaging combined extortion claims with overt political themes, including claims of data theft and threats to leak stolen information, reinforcing the assessment that DarkBit served both disruptive and psychological objectives in operations aligned with Iranian geopolitical interests.

DarkBit primarily targets Windows environments and has been associated with attacks against Israeli organizations and broader disruptive operations attributed to Iranian threat actors. Its significance lies not only in its encryption capability but also in its role as a state-linked ransomware facade blending espionage tradecraft, destructive intent, and information operations.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Post Exploitation

Operational record

1
YARA rules
1
Ransom notes
1
Leak sites
0 available

Reported operators

Threat actors

2 named in public reporting
MuddyWater

Recently, we came across a tweet about DarkBit ransomware. An Iranian APT group, named MuddyWater, is reportedly behind the DarkBit ransomware.

MITRE ATT&CK

DarkBit in ATT&CK

12 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.