Storm-1084 Iran DarkBit
DarkBit
DarkBit is a ransomware persona/group launched in 2023 that has been used in destructive cyber operations rather than conventional financially motivated ransomware activity.
Profile source: Mallory opens in a new tabDarkBit
Family profile
DarkBit is a ransomware persona/group launched in 2023 that has been used in destructive cyber operations rather than conventional financially motivated ransomware activity. Multiple sources in the provided content link DarkBit to Iranian state-sponsored activity, specifically DEV-1084/Storm-1084 and MOIS-linked actors, with collaboration or association noted with MERCURY, now tracked as Mango Sandstorm/MuddyWater. The DarkBit persona was used in the February 2023 attack on the Technion Israel Institute of Technology in Israel, which Microsoft and other reporting described as a destructive operation masquerading as ransomware. Supporting content also states that DarkBit is believed to be associated with the MuddyWater Iranian espionage group and is cited as an example of Iran using fronts/personas to claim responsibility for disruptive attacks. Reported capabilities and characteristics in the content include ransomware-style encryption, but researchers and Israeli security firm Profero developed/deployed decryptors after identifying a weak key generation algorithm that allowed brute-forcing of the decryption key. High-confidence targeting reflected in the content includes Israeli organizations, specifically Technion, within the broader context of Iranian operations against regional adversaries and critical or strategic sectors. No additional specific IOCs are provided in the supplied content.
Operational record
Reported operators
Threat actors
2 named in public reporting...it has also been linked to disruptive operations targeting the Technion Israel Institute of Technology by adopting the DarkBit ransomware persona.