DarkSide was a Russian-speaking ransomware-as-a-service operation that emerged in 2020 and became one of the most prominent big-game hunting cybercriminal groups before its public shutdown in 2021 following the Colonial Pipeline incident. The group is widely associated with financially motivated extortion and is commonly linked in reporting to later ransomware brands including BlackMatter, while some assessments also place personnel or tradecraft continuity into ALPHV/BlackCat. DarkSide operated an affiliate model, recruited initial access brokers and penetration-oriented partners on Russian-language criminal forums, and reportedly offered affiliates a large share of ransom proceeds. The malware and operations were designed to avoid systems in Commonwealth of Independent States countries, consistent with a Russia-based criminal ecosystem orientation. DarkSide primarily targeted large private-sector organizations capable of paying multimillion-dollar ransoms, with a strong emphasis on North American and European victims and explicit interest in large U.S. enterprises. The group is best known for the 2021 attack on Colonial Pipeline, which caused major fuel distribution disruption in the United States and drew intense law-enforcement and government attention. DarkSide also maintained a leak site and used stolen data to pressure victims, making double extortion a core part of its operating model. Reporting also indicates the group at times used additional pressure tactics including distributed denial-of-service activity and direct contact with victims’ customers, amounting to escalated multi-vector extortion. Technically, DarkSide supported both Windows and Linux environments and expanded to target VMware ESXi infrastructure, reflecting the broader ransomware trend toward virtualization-focused impact. The malware family has been described as using partial encryption to accelerate attacks, deleting shadow copies, terminating processes and services that could interfere with encryption, collecting host information, and generating victim-specific identifiers and ransom-note artifacts. DarkSide operators and affiliates were also observed using reconnaissance tooling such as Advanced IP Scanner, and the group sought access through brokers as well as compromised enterprise credentials. Public reporting further indicates that the actors behind DarkSide had previously distributed REvil ransomware before creating their own operation. After the Colonial Pipeline attack, DarkSide stated that it lost control of parts of its infrastructure and some ransom proceeds, then abandoned public operations amid pressure from authorities and cybercrime forum restrictions on ransomware advertising. Subsequent reporting repeatedly assessed BlackMatter as a repaint, successor, or rebrand of DarkSide based on code, payload similarity, tradecraft, and operational overlap. DarkSide is therefore best understood as a major financially motivated RaaS brand within the Russian-speaking ransomware ecosystem whose personnel, tooling, and methods likely persisted under successor operations after the original brand disappeared.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
50 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
73 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as another ransomware operation that faced pressure after the Colonial Pipeline attack.
Operating a ransomware affiliate program, recruiting affiliates and initial access brokers, running a leak site for extortion, and targeting large organizations for big-game ransomware attacks.
Referenced as the predecessor/continuation lineage for BlackMatter; BlackMatter is described as nearly identical to the latest DarkSide version in its earliest iteration.
Mentioned as a comparison and in discussion of possible operational similarities with BlackCat.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.