Skip to content

Darkside

DarkSide is a human-operated ransomware family and ransomware-as-a-service operation active from approximately August 2020 until May 2021.

Profile source: Mallory opens in a new tab

Darkside

Family profile

DarkSide is a human-operated ransomware family and ransomware-as-a-service operation active from approximately August 2020 until May 2021. Affiliates conducted intrusions and deployed configurable encryptors against large private-sector organizations, while the core operation supplied ransomware and extortion infrastructure. DarkSide used double extortion: it encrypted victim data, exfiltrated sensitive information, and threatened public disclosure through a leak site if payment was not made. The ransomware targeted Windows and Linux systems, including Linux environments used to affect virtualized enterprise infrastructure. DarkSide sought access to large U.S. businesses through initial-access brokers and reportedly avoided systems configured for Commonwealth of Independent States countries. It was responsible for the May 2021 Colonial Pipeline attack, which caused an operational shutdown and fuel-supply disruption in the United States. BlackMatter was widely assessed as a successor or rebrand of DarkSide, and subsequent reporting has identified technical and operational lineage connecting DarkSide, BlackMatter, and BlackCat/ALPHV.

Capabilities

  • Exfiltration
  • Extortion

Operational record

1
YARA rules
1
Ransom notes
5
Negotiations
1
Leak sites
0 available

Credential Theft

  • Mimikatz
  • SessionGopher

Discovery Enum

  • ADRecon
  • AdFind
  • Advanced IP Scanner
  • SoftPerfect NetScan

Exfiltration

  • Bashupload
  • MEGA
  • RClone
  • Sendspace
  • pCloud

LOLBAS

  • PsExec

Networking

  • Plink

Offsec

  • Cobalt Strike
  • CrackMapExec
  • Impacket
  • PowerSploit

RMM Tools

  • AnyDesk
  • GoToAssist
  • TightVNC

Reported operators

Threat actors

9 named in public reporting
FIN7

FIN7 has attempted to run Darkside ransomware with the filename sleep.exe.

UNC24655

SMOKEDHAM ... a été utilisée par UNC24655, un affilié RaaS précédemment associé aux groupes Lockbit et Darkside.

DarkSide

On Sunday, May 9th Dragos released an intel report to our customers that assessed with high confidence that the DarkSide ransomware group was responsible for the IT compromise.

Coreid

BlackMatter is linked to the Coreid cyber crime group, which was previously responsible for the Darkside ransomware.

DEV-0289

ELBRUS developed their own RaaS ecosystem named DarkSide. They deployed DarkSide payloads as part of their operations and recruited and managed affiliates that deployed the DarkSide ransomware.

UNC2465

FireEye researchers documented five separate clusters of activity suspected of being connected to DarkSide, the Ransomware-as-a-Service (RaaS) network responsible for the Colonial Pipeline security incident.

UNC2628

FireEye researchers documented five separate clusters of activity suspected of being connected to DarkSide, the Ransomware-as-a-Service (RaaS) network responsible for the Colonial Pipeline security incident.

UNC2659

FireEye researchers documented five separate clusters of activity suspected of being connected to DarkSide, the Ransomware-as-a-Service (RaaS) network responsible for the Colonial Pipeline security incident.

Wazawaka

Wazawaka also said he’d teamed up with DarkSide, the ransomware affiliate group responsible for the six-day outage at Colonial Pipeline last year that caused nationwide fuel shortages and price spikes.

Exploited software

Vulnerabilities linked to Darkside

2 CVEs

MITRE ATT&CK

Darkside in ATT&CK

100 distinct techniques

Techniques

100 techniques
T1486 Data Encrypted for Impact T1041 Exfiltration Over C2 Channel T1003 OS Credential Dumping T1537 Transfer Data to Cloud Account T1657 Financial Theft T1133 External Remote Services T1218 System Binary Proxy Execution T1078 Valid Accounts T1490 Inhibit System Recovery T1489 Service Stop T1497 Virtualization/Sandbox Evasion T1036 Masquerading T1573 Encrypted Channel T1567 Exfiltration Over Web Service T1482 Domain Trust Discovery T1552.001 Credentials In Files T1059.001 PowerShell T1027 Obfuscated Files or Information T1071 Application Layer Protocol T1057 Process Discovery T1134 Access Token Manipulation T1112 Modify Registry T1480.002 Mutual Exclusion T1548.002 Bypass User Account Control T1082 System Information Discovery T1059 Command and Scripting Interpreter T1199 Trusted Relationship T1614.001 System Language Discovery T1027.007 Dynamic API Resolution T1120 Peripheral Device Discovery T1012 Query Registry T1491 Defacement T1055 Process Injection T1203 Exploitation for Client Execution T1068 Exploitation for Privilege Escalation T1020.001 Traffic Duplication T1070.004 File Deletion T1001 Data Obfuscation T1543.003 Windows Service T1021 Remote Services T1567.003 Exfiltration to Text Storage Sites T1083 File and Directory Discovery T1491.001 Internal Defacement T1070 Indicator Removal T1553.004 Install Root Certificate T1105 Ingress Tool Transfer T1529 System Shutdown/Reboot T1570 Lateral Tool Transfer T1498 Network Denial of Service T1018 Remote System Discovery T1071.001 Web Protocols T1005 Data from Local System T1135 Network Share Discovery T1033 System Owner/User Discovery T1046 Network Service Discovery T1074 Data Staged T1583 Acquire Infrastructure T1497.001 System Checks T1114 Email Collection T1190 Exploit Public-Facing Application T1589 Gather Victim Identity Information T1129 Shared Modules T1021.002 SMB/Windows Admin Shares T1569.002 Service Execution T1007 System Service Discovery T1204.002 Malicious File T1027.013 Encrypted/Encoded File T1053.005 Scheduled Task T1485 Data Destruction T1021.001 Remote Desktop Protocol T1566 Phishing T1587 Develop Capabilities T1047 Windows Management Instrumentation T1016 System Network Configuration Discovery T1568 Dynamic Resolution T1048 Exfiltration Over Alternative Protocol T1588.001 Malware T1592 Gather Victim Host Information T1071.004 DNS T1090.003 Multi-hop Proxy T1484.001 Group Policy Modification T1562 Impair Defenses T1567.002 Exfiltration to Cloud Storage T1598 Phishing for Information T1021.004 SSH T1583.006 Web Services T1614 System Location Discovery T1562.001 Disable or Modify Tools T1574 Hijack Execution Flow T1053.003 Cron T1598.004 Spearphishing Voice T1548 Abuse Elevation Control Mechanism T1074.001 Local Data Staging T1548.003 Sudo and Sudo Caching T1140 Deobfuscate/Decode Files or Information T1546.001 Change Default File Association T1003.001 OS Credential Dumping: LSASS Memory T1003.003 OS Credential Dumping: NTDS T1560.001 Archive Collected Data: Archive via Utility T1219 Remote Access Software

Reporting

Research mentioning Darkside

Jan 1
Sandfly Security

BPFDoor - An Evasive Linux Backdoor Technical Analysis

Security researchers detailed BPFDoor, a stealthy Linux backdoor attributed by PwC to the China-linked group Red Menshen, describing its use in long-running intrusions against telecommunications, government, logistics, and education organizations in the Middle East and Asia. The malware is designed for covert re-entry and persistence, using raw sockets and Berkeley Packet Filter (BPF) logic to inspect network traffic for specially crafted magic packets, then launching a reverse shell, bind shell, or pingback without exposing obvious new listening services. Researchers said BPFDoor can hide behind legitimate network activity by listening on traffic destined for existing services such as 443, allowing operators to execute commands while avoiding conspicuous firewall or port changes. Analysis showed the malware often copies itself into /dev/shm, deletes the original binary, spoofs process names, creates PID files under /var/run, and can temporarily alter iptables to hijack traffic for command and control; historical samples appeared functionally stable over time, with changes largely limited to hardcoded passwords, filenames, and process names. Elastic and other researchers published hunting guidance, YARA signatures, and tooling to help defenders identify infections.

Jan 1
Sophos Threat Research

Sophos MTR in Real Time: What is Astro Locker Team? | SOPHOS

Mount Locker emerged as a corporate-targeting ransomware operation that stole data before encrypting files and then demanded multi-million dollar payments while threatening to leak stolen information on a Tor-hosted extortion site. Reporting on early victims said the group had already listed multiple organizations on its leak portal and published at least one victim’s files after nonpayment. The malware used ChaCha20 for file encryption and an embedded RSA-2048 public key to protect encryption material, dropped a ransom note named RecoveryManual.html, and appended a .ReadManual.ID-style extension to encrypted files. Reverse-engineering of Mount Locker samples and later variants showed the ransomware also included operational features for enterprise-wide impact, including command-line options for targeting hosts, suppressing logs, avoiding process termination controls, and encrypting network resources. Analysts reported that newer builds added worm-like lateral movement by enumerating domain or network systems, requiring /LOGIN= and /PASSWORD= parameters for propagation, copying itself to remote machines, creating services named in an Update{GetTickCount()} pattern, and in some cases launching remotely through WMI under ROOT\CIMV2. The malware was also described as killing selected services and processes before encryption to maximize disruption.

Jul 31
Malpedia

Clop (Malware Family)

Ukrainian authorities, working with law enforcement partners in the United States and South Korea, arrested six suspected members of the Clop ransomware operation and conducted 21 searches in Kyiv and surrounding areas. Investigators said they seized computers, smartphones, server equipment, cash, and luxury vehicles, and shut down infrastructure allegedly used in earlier attacks. The suspects were reported to face prison terms of up to eight years if convicted. The action targeted a group tied to ransomware and data-extortion attacks dating back to 2019, including incidents involving South Korean companies and the attack on retailer E-Land. Reporting also linked Clop to the exploitation of four zero-day vulnerabilities in Accellion FTA, intrusions that led to data theft and extortion affecting organizations including Kroger, Jones Day, Qualys, Singtel, Stanford University Medical School, the University of California, and the University of Maryland. Researchers and investigators have described Clop as a major double-extortion operation, though some assessments said the raids likely disrupted affiliates and money-laundering elements more than the group’s core leadership.

Jun 2
Haxrob

BPFDoor - Part 2 - The Present

Mar 22
Sentinelone Labs Subdomain

Multi-Platform SMAUG RaaS Aims To See Off Competitors - SentinelLabs

SMAUG is a ransomware-as-a-service (RaaS) operation that advertises 64-bit payloads for Windows, Linux, and macOS, positioning itself as a multi-platform option for affiliates. The service reportedly charges a 20% affiliate fee plus a 0.2 BTC registration fee, and provides a web-based campaign builder, customizable ransom demands, offline encryption, and a "Company Mode" that allows a single decryption key to unlock multiple systems inside one targeted organization. Victims are directed to a Tor-based payment portal, while operators reportedly offer automated support for both affiliates and victims and bar attacks against CIS countries. On Windows, SMAUG uses obfuscated Go binaries that gather system details and stored browser credentials, establish persistence through Registry Run Keys consistent with MITRE ATT&CK T1547.001, and then encrypt files for impact using AES-256 with keys protected by RSA-2048, aligning with T1486 Data Encrypted for Impact tradecraft. The combination of credential collection, registry-based autostart, and hybrid cryptography reflects a mature ransomware model designed to support repeatable intrusions and broad enterprise targeting across multiple operating systems.

Jan 23
Trend Micro Research

Kasseika Ransomware Deploys BYOVD Attacks Abuses PsExec and Exploits Martini Driver | Trend Micro (US)

Trend Micro reported that the Kasseika ransomware used a bring-your-own-vulnerable-driver (BYOVD) technique to compromise Windows environments, disable security tools, and encrypt victim files. In the investigated intrusion, the attackers reportedly gained initial access through targeted phishing, then used remote administration tools and PsExec for execution and lateral movement. The malware abused the signed but vulnerable Martini.sys driver from TG Soft’s VirIT Agent System to terminate antivirus and analysis processes, allowing the ransomware to run with reduced interference. The operation also employed anti-analysis checks, cleared Windows event logs, and deleted shadow copies before encrypting files with ChaCha20 and RSA through CryptoPP. After encryption, Kasseika dropped ransom notes and changed the victim’s desktop wallpaper. Researchers said the malware shares multiple code and behavioral traits with BlackMatter, including ransom note naming conventions and apparent source-code overlap, indicating the operators may have obtained or reused parts of BlackMatter’s codebase.

May 11
Bleeping Computer

Stealthier version of Linux BPFDoor malware spotted in the wild

Jul 13
Elastic Security Labs

A peek behind the BPFDoor - Elastic Security Labs

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.