Skip to content

Darkside

DarkSide is a ransomware-as-a-service operation that emerged in 2020 and became widely known for the 2021 Colonial Pipeline incident.

Profile source: Mallory opens in a new tab

Darkside

Family profile

DarkSide is a ransomware-as-a-service operation that emerged in 2020 and became widely known for the 2021 Colonial Pipeline incident. It operated through a core developer team and affiliates, with the operators providing ransomware tooling and management infrastructure while affiliates conducted intrusions and deployments. DarkSide is associated with financially motivated double-extortion activity in which victim data is stolen before encryption and later used to pressure payment through threatened publication. Public reporting has linked the operation to dozens of intrusions and to targeting of enterprises in sectors including energy and other large organizations, with especially high-profile impact on critical infrastructure through the Colonial Pipeline disruption.

DarkSide intrusions have been associated with multiple initial access methods depending on the affiliate, including use of stolen or phished credentials, credential-based VPN access, brute-force activity, exploitation of CVE-2021-20016 on SonicWall SMA100 appliances, and phishing-delivered backdoor access. Once inside a network, affiliates have been observed maintaining dwell time ranging from a few days to several weeks, conducting reconnaissance, exfiltrating data, and moving laterally with administrative protocols and remote access mechanisms such as RDP, SSH, and PSExec. Reported affiliate tradecraft also included persistence through remote administration software and use of commodity or dual-use tooling such as Cobalt Strike and SystemBC.

The malware supports both Windows and Linux environments. The Windows variant encrypts files, attempts privilege escalation via the CMSTPLUA technique when needed, terminates backup, mail, and database-related services to maximize impact, tampers with security tooling, and deletes Volume Shadow Copies to inhibit recovery. The Linux variant is an ELF payload that has been reported targeting VMware virtualized environments by encrypting VMDK files on ESXi systems. DarkSide’s operational model and technical behavior place it among the more mature ransomware families of its period, combining enterprise-focused intrusion tradecraft with extortion infrastructure and affiliate management.

DarkSide publicly claimed to be apolitical and profit-driven and stated that it avoided certain victim categories, but its affiliate model limited centralized control over target selection and operational consequences. The operation is widely assessed as part of the Russian-speaking cybercriminal ecosystem, though publicly available information does not establish it as a state-directed capability. The group became defunct after intense law-enforcement and public scrutiny following Colonial Pipeline, including a U.S. Department of Justice seizure of part of the ransom proceeds.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Extortion
  • Lateral Movement
  • Persistence
  • Privilege Escalation

Operational record

1
YARA rules
1
Ransom notes
5
Negotiations
1
Leak sites
0 available

Credential Theft

  • Mimikatz
  • SessionGopher

Discovery Enum

  • ADRecon
  • AdFind
  • Advanced IP Scanner
  • SoftPerfect NetScan

Exfiltration

  • Bashupload
  • MEGA
  • RClone
  • Sendspace
  • pCloud

LOLBAS

  • PsExec

Networking

  • Plink

Offsec

  • Cobalt Strike
  • CrackMapExec
  • Impacket
  • PowerSploit

RMM Tools

  • AnyDesk
  • GoToAssist
  • TightVNC

Reported operators

Threat actors

7 named in public reporting
FIN7

In 2023, FIN7 expanded its operations to include the deployment of ransomware through affiliations with RaaS groups such as REvil and Maze, while also managing its own RaaS programs, including the now-retired Darkside and BlackMatter.

DEV-0289

ELBRUS developed their own RaaS ecosystem named DarkSide. They deployed DarkSide payloads as part of their operations and recruited and managed affiliates that deployed the DarkSide ransomware.

UNC2465

FireEye researchers documented five separate clusters of activity suspected of being connected to DarkSide, the Ransomware-as-a-Service (RaaS) network responsible for the Colonial Pipeline security incident.

UNC2628

FireEye researchers documented five separate clusters of activity suspected of being connected to DarkSide, the Ransomware-as-a-Service (RaaS) network responsible for the Colonial Pipeline security incident.

UNC2659

FireEye researchers documented five separate clusters of activity suspected of being connected to DarkSide, the Ransomware-as-a-Service (RaaS) network responsible for the Colonial Pipeline security incident.

DarkSide

The attack began when a hacker group identified as DarkSide accessed the Colonial Pipeline network. The attackers stole 100 gigabytes of data within a two-hour window. Following the data theft, the attackers infected the Colonial Pipeline IT network with ransomware that affected many computer systems, including billing and accounting.

Wazawaka

Wazawaka also said he’d teamed up with DarkSide, the ransomware affiliate group responsible for the six-day outage at Colonial Pipeline last year that caused nationwide fuel shortages and price spikes.

Exploited software

Vulnerabilities linked to Darkside

1 CVEs

MITRE ATT&CK

Darkside in ATT&CK

51 distinct techniques

Techniques

51 techniques
T1105 Ingress Tool Transfer T1082 System Information Discovery T1562 Impair Defenses T1567.002 Exfiltration to Cloud Storage T1059 Command and Scripting Interpreter T1489 Service Stop T1486 Data Encrypted for Impact T1021.002 SMB/Windows Admin Shares T1033 System Owner/User Discovery T1074 Data Staged T1021.001 Remote Desktop Protocol T1570 Lateral Tool Transfer T1112 Modify Registry T1598 Phishing for Information T1078 Valid Accounts T1070.004 File Deletion T1021.004 SSH T1068 Exploitation for Privilege Escalation T1048 Exfiltration Over Alternative Protocol T1583.006 Web Services T1537 Transfer Data to Cloud Account T1071 Application Layer Protocol T1566 Phishing T1657 Financial Theft T1614 System Location Discovery T1041 Exfiltration Over C2 Channel T1548.002 Bypass User Account Control T1562.001 Disable or Modify Tools T1490 Inhibit System Recovery T1574 Hijack Execution Flow T1543.003 Windows Service T1614.001 System Language Discovery T1053.003 Cron T1059.001 PowerShell T1498 Network Denial of Service T1598.004 Spearphishing Voice T1548 Abuse Elevation Control Mechanism T1027 Obfuscated Files or Information T1047 Windows Management Instrumentation T1074.001 Local Data Staging T1548.003 Sudo and Sudo Caching T1140 Deobfuscate/Decode Files or Information T1546.001 Change Default File Association T1190 Exploit Public-Facing Application T1003.001 OS Credential Dumping: LSASS Memory T1003.003 OS Credential Dumping: NTDS T1046 Network Service Discovery T1482 Domain Trust Discovery T1560.001 Archive Collected Data: Archive via Utility T1071.001 Application Layer Protocol: Web Protocols T1219 Remote Access Software

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.