Dark Angels is a financially motivated, Russian-speaking cybercriminal operation active since May 2022. Also known as DarkAngels and the Dunghill Leak group, it targets large enterprises worldwide, including U.S. corporations and industrial companies. It operates the Dunghill Leaks data-leak site to pressure victims through threatened publication of stolen information. The group conducts its own intrusions rather than operating a ransomware-as-a-service program or relying on affiliates. Dark Angels follows a selective big-game-hunting strategy, concentrating on a small number of high-value organizations. Operators compromise corporate networks, move laterally, obtain administrative access, and exfiltrate large volumes of data for extortion. In encryption-based attacks, they use domain-controller access to deploy ransomware across the victim environment. The group initially used Babuk-derived Windows and VMware ESXi encryptors and subsequently adopted a Linux encryptor associated with Ragnar Locker. Its ransomware can encrypt local storage, network shares, and mapped drives; enumerate system information, services, and processes; terminate applications and services; and delete shadow copies to impede recovery. The operation uses both double extortion and encryption-less data-theft extortion. In its 2023 attack on Johnson Controls, Dark Angels encrypted VMware ESXi systems and claimed to have stolen 27 TB of corporate data. In early 2024, it exfiltrated approximately 100 TB from a large publicly traded U.S. company and received a $75 million payment without deploying ransomware. That payment was confirmed as the largest publicly recorded ransom payment at the time.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
13 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware operations described as using ESXi-specific variants and refined hypervisor targeting, including backup destruction and high-impact disruption.
Dark Angels is a ransomware group known for demanding and receiving large ransom payments, such as the reported $75 million, which has influenced the broader ransomware ecosystem to pursue higher payouts.
Conducting large-scale data theft and extortion operations, including theft of massive data volumes from major corporations.
Ransomware/extortion group associated in the content with a record-breaking $75 million ransom payment in H1 2024.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.