DARKSTAR is a ransomware threat actor also tracked as COMET and Shadow. It is associated with classic double-extortion operations, combining data theft with ransomware deployment to pressure victims. Reporting has identified infrastructural and tactical overlaps between DARKSTAR and the hacktivist cluster Twelve, suggesting the groups may be related or part of the same broader activity cluster, although DARKSTAR itself is characterized as following a conventional financially motivated ransomware model rather than Twelve’s destructive hacktivist pattern. High-confidence public reporting in this context supports DARKSTAR’s use of double extortion and its association with a broader cluster that shares tooling, infrastructure, and tradecraft with other intrusion sets, but does not provide sufficient corroborated detail here to attribute additional specific techniques, victimology, or geography to DARKSTAR alone.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware group linked by shared infrastructure, utilities, and TTPs with Twelve, but operating with a classic double-extortion model rather than hacktivist destructive objectives.
Ransomware intrusion set associated (infrastructure/TTP overlaps) with Twelve; described as following a classic double-extortion model (encrypt + data theft/extortion).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.