DarkSide, also listed as darkside_group, is a financially motivated cybercriminal ransomware operation first observed in August 2020. It operated a ransomware-as-a-service program in which core operators developed company-specific ransomware builds and maintained infrastructure, while affiliates compromised organizations and deployed the malware. Its extortion model combined file encryption with data theft and threats to publish stolen information through a data-leak site. Historically associated affiliates include UNC2465, and the operation also had links to FIN7 and Clop within the wider cybercrime ecosystem. DarkSide is best known for the May 7, 2021 attack on Colonial Pipeline in the United States, conducted through its affiliate program. The compromise affected business IT systems and prompted a precautionary pipeline shutdown, disrupting fuel distribution across the U.S. East Coast for several days. The attack involved data theft and resulted in a multimillion-dollar ransom payment. The supplied decryptor proved slower than Colonial Pipeline's own recovery tools, and U.S. authorities subsequently recovered a substantial portion of the ransom proceeds. DarkSide publicly claimed to prohibit attacks against hospitals, schools, and government organizations, but its affiliate model limited effective control over victim selection. Following the Colonial Pipeline incident and heightened law-enforcement scrutiny, it announced the closure of its affiliate program in May 2021 after reporting loss of control over public-facing infrastructure. Its personnel and affiliate network had connections to later ransomware operations: the FBI linked ALPHV developers and money launderers to DarkSide and BlackMatter. These relationships should not be treated as evidence that the operations were interchangeable.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
47 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
77 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware group that attacked Colonial Pipeline, reportedly stole data before encryption, and disrupted pipeline operations for approximately six days.
Referenced as another ransomware operation that faced pressure after the Colonial Pipeline attack.
Operating a ransomware affiliate program, recruiting affiliates and initial access brokers, running a leak site for extortion, and targeting large organizations for big-game ransomware attacks.
Referenced as the predecessor/continuation lineage for BlackMatter; BlackMatter is described as nearly identical to the latest DarkSide version in its earliest iteration.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.