Credential Theft
- Mimikatz
- SessionGopher
DarkSide is a human-operated ransomware family and ransomware-as-a-service operation active from approximately August 2020 until May 2021.
Profile source: Mallory opens in a new tabDarkside
DarkSide is a human-operated ransomware family and ransomware-as-a-service operation active from approximately August 2020 until May 2021. Affiliates conducted intrusions and deployed configurable encryptors against large private-sector organizations, while the core operation supplied ransomware and extortion infrastructure. DarkSide used double extortion: it encrypted victim data, exfiltrated sensitive information, and threatened public disclosure through a leak site if payment was not made. The ransomware targeted Windows and Linux systems, including Linux environments used to affect virtualized enterprise infrastructure. DarkSide sought access to large U.S. businesses through initial-access brokers and reportedly avoided systems configured for Commonwealth of Independent States countries. It was responsible for the May 2021 Colonial Pipeline attack, which caused an operational shutdown and fuel-supply disruption in the United States. BlackMatter was widely assessed as a successor or rebrand of DarkSide, and subsequent reporting has identified technical and operational lineage connecting DarkSide, BlackMatter, and BlackCat/ALPHV.
Reported operators
FIN7 has attempted to run Darkside ransomware with the filename sleep.exe.
SMOKEDHAM ... a été utilisée par UNC24655, un affilié RaaS précédemment associé aux groupes Lockbit et Darkside.
On Sunday, May 9th Dragos released an intel report to our customers that assessed with high confidence that the DarkSide ransomware group was responsible for the IT compromise.
BlackMatter is linked to the Coreid cyber crime group, which was previously responsible for the Darkside ransomware.
ELBRUS developed their own RaaS ecosystem named DarkSide. They deployed DarkSide payloads as part of their operations and recruited and managed affiliates that deployed the DarkSide ransomware.
FireEye researchers documented five separate clusters of activity suspected of being connected to DarkSide, the Ransomware-as-a-Service (RaaS) network responsible for the Colonial Pipeline security incident.
FireEye researchers documented five separate clusters of activity suspected of being connected to DarkSide, the Ransomware-as-a-Service (RaaS) network responsible for the Colonial Pipeline security incident.
FireEye researchers documented five separate clusters of activity suspected of being connected to DarkSide, the Ransomware-as-a-Service (RaaS) network responsible for the Colonial Pipeline security incident.
Wazawaka also said he’d teamed up with DarkSide, the ransomware affiliate group responsible for the six-day outage at Colonial Pipeline last year that caused nationwide fuel shortages and price spikes.
Exploited software
MITRE ATT&CK
Reporting
Security researchers detailed BPFDoor, a stealthy Linux backdoor attributed by PwC to the China-linked group Red Menshen, describing its use in long-running intrusions against telecommunications, government, logistics, and education organizations in the Middle East and Asia. The malware is designed for covert re-entry and persistence, using raw sockets and Berkeley Packet Filter (BPF) logic to inspect network traffic for specially crafted magic packets, then launching a reverse shell, bind shell, or pingback without exposing obvious new listening services. Researchers said BPFDoor can hide behind legitimate network activity by listening on traffic destined for existing services such as 443, allowing operators to execute commands while avoiding conspicuous firewall or port changes. Analysis showed the malware often copies itself into /dev/shm, deletes the original binary, spoofs process names, creates PID files under /var/run, and can temporarily alter iptables to hijack traffic for command and control; historical samples appeared functionally stable over time, with changes largely limited to hardcoded passwords, filenames, and process names. Elastic and other researchers published hunting guidance, YARA signatures, and tooling to help defenders identify infections.
Mount Locker emerged as a corporate-targeting ransomware operation that stole data before encrypting files and then demanded multi-million dollar payments while threatening to leak stolen information on a Tor-hosted extortion site. Reporting on early victims said the group had already listed multiple organizations on its leak portal and published at least one victim’s files after nonpayment. The malware used ChaCha20 for file encryption and an embedded RSA-2048 public key to protect encryption material, dropped a ransom note named RecoveryManual.html, and appended a .ReadManual.ID-style extension to encrypted files. Reverse-engineering of Mount Locker samples and later variants showed the ransomware also included operational features for enterprise-wide impact, including command-line options for targeting hosts, suppressing logs, avoiding process termination controls, and encrypting network resources. Analysts reported that newer builds added worm-like lateral movement by enumerating domain or network systems, requiring /LOGIN= and /PASSWORD= parameters for propagation, copying itself to remote machines, creating services named in an Update{GetTickCount()} pattern, and in some cases launching remotely through WMI under ROOT\CIMV2. The malware was also described as killing selected services and processes before encryption to maximize disruption.
Ukrainian authorities, working with law enforcement partners in the United States and South Korea, arrested six suspected members of the Clop ransomware operation and conducted 21 searches in Kyiv and surrounding areas. Investigators said they seized computers, smartphones, server equipment, cash, and luxury vehicles, and shut down infrastructure allegedly used in earlier attacks. The suspects were reported to face prison terms of up to eight years if convicted. The action targeted a group tied to ransomware and data-extortion attacks dating back to 2019, including incidents involving South Korean companies and the attack on retailer E-Land. Reporting also linked Clop to the exploitation of four zero-day vulnerabilities in Accellion FTA, intrusions that led to data theft and extortion affecting organizations including Kroger, Jones Day, Qualys, Singtel, Stanford University Medical School, the University of California, and the University of Maryland. Researchers and investigators have described Clop as a major double-extortion operation, though some assessments said the raids likely disrupted affiliates and money-laundering elements more than the group’s core leadership.
SMAUG is a ransomware-as-a-service (RaaS) operation that advertises 64-bit payloads for Windows, Linux, and macOS, positioning itself as a multi-platform option for affiliates. The service reportedly charges a 20% affiliate fee plus a 0.2 BTC registration fee, and provides a web-based campaign builder, customizable ransom demands, offline encryption, and a "Company Mode" that allows a single decryption key to unlock multiple systems inside one targeted organization. Victims are directed to a Tor-based payment portal, while operators reportedly offer automated support for both affiliates and victims and bar attacks against CIS countries. On Windows, SMAUG uses obfuscated Go binaries that gather system details and stored browser credentials, establish persistence through Registry Run Keys consistent with MITRE ATT&CK T1547.001, and then encrypt files for impact using AES-256 with keys protected by RSA-2048, aligning with T1486 Data Encrypted for Impact tradecraft. The combination of credential collection, registry-based autostart, and hybrid cryptography reflects a mature ransomware model designed to support repeatable intrusions and broad enterprise targeting across multiple operating systems.
Trend Micro reported that the Kasseika ransomware used a bring-your-own-vulnerable-driver (BYOVD) technique to compromise Windows environments, disable security tools, and encrypt victim files. In the investigated intrusion, the attackers reportedly gained initial access through targeted phishing, then used remote administration tools and PsExec for execution and lateral movement. The malware abused the signed but vulnerable Martini.sys driver from TG Soft’s VirIT Agent System to terminate antivirus and analysis processes, allowing the ransomware to run with reduced interference. The operation also employed anti-analysis checks, cleared Windows event logs, and deleted shadow copies before encrypting files with ChaCha20 and RSA through CryptoPP. After encryption, Kasseika dropped ransom notes and changed the victim’s desktop wallpaper. Researchers said the malware shares multiple code and behavioral traits with BlackMatter, including ransom note naming conventions and apparent source-code overlap, indicating the operators may have obtained or reused parts of BlackMatter’s codebase.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.