DarkSide is a financially motivated ransomware family and ransomware-as-a-service operation first observed around August 2020. Its operators developed ransomware, supplied attack infrastructure, and built customized executables for individual victims, while affiliates compromised organizations and deployed the malware. DarkSide encrypts victim data to support ransom demands and maintained a public data-leak site. A variant has been used by FIN7 to encrypt virtual disk volumes on VMware ESXi servers. Its targeting has included industrial organizations in transportation, oil and gas, and manufacturing.
DarkSide affiliates carried out the May 7, 2021 attack against Colonial Pipeline, which prompted the company to halt pipeline operations and disrupted fuel distribution across the United States East Coast. This disruption followed an IT compromise rather than an established direct attack on pipeline control systems. DarkSide announced the closure of its affiliate program in May 2021 after heightened scrutiny and loss of control over public-facing infrastructure. Although the operation publicly prohibited attacks on certain healthcare, education, and government organizations, those restrictions did not prevent a major critical-infrastructure incident. BlackMatter subsequently exhibited substantial similarities in code and affiliate structure, and the FBI linked ALPHV/BlackCat developers and money launderers to DarkSide and BlackMatter.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In others, the CVE-2019-1579 vulnerability in Palo Alto’s GlobalProtect portal and GlobalProtect Gateway interface products and Microsoft Exchange server exposure were used. As a result of exploitation, an unauthenticated attacker could execute malicious code remotely (RCE). | DarkSide ransomware recently attacked the Colonial Pipeline — the largest pipeline in the United States... DarkSide stands out from other ransomware as a service (RaaS) threats, as one of the attack vectors is based on the Zloader botnet (also known as “Silent Night”).
Since initially surfacing in August 2020, the creators of DARKSIDE ransomware and their affiliates have launched a global crime spree affecting organizations in more than 15 countries and multiple industry verticals. | The threat actor obtained initial access to their victim by exploiting CVE-2021-20016, an exploit in the SonicWall SMA100 SSL VPN product, which has been patched by SonicWall. There is some evidence to suggest the threat actor may have used the vulnerability to disable multi-factor authentication options on the SonicWall VPN, although this has not been confirmed.
9 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
FIN7 has encrypted virtual disk volumes on ESXi servers using a version of Darkside ransomware.
The FBI confirmed on Monday that the criminal group responsible is leveraging the DarkSide RaaS (Ransomware-as-a-Service).
While UNC2465 was historically affiliated to the DarkSide Ransomware-as-a-Service (RaaS), we suspect it might also have been associated with the following RaaS: LockBit, and Hunters International.
SMOKEDHAM ... a été utilisée par UNC24655, un affilié RaaS précédemment associé aux groupes Lockbit et Darkside.
BlackMatter is linked to the Coreid cyber crime group, which was previously responsible for the Darkside ransomware.
ELBRUS developed their own RaaS ecosystem named DarkSide. They deployed DarkSide payloads as part of their operations and recruited and managed affiliates that deployed the DarkSide ransomware.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
operators have gained entry through insecure remote access services using compromised credentials.
Stealth tactics include: ... Obfuscation techniques like encoding and dynamic library loading
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
operators have gained entry through insecure remote access services using compromised credentials.
Once inside the network, attackers used known techniques for increasing access and compromising the network, including Living-off-the-Land Binaries (LOLbins) and offensive security tools such as Cobalt Strike, Mimikatz and others.
The malware creates a mutex called “Global\4787658f1cc4202b8a15e05dd0323fde”, which makes sure that there is only one instance of the ransomware running at a time.
By targeting virtual machines, ransomware operators can also encrypt multiple servers at once with a single command. In June, researchers spotted a new REvil ransomware Linux encryptor designed to target VMware ESXi virtual machines, a popular enterprise virtual machine platform.
They emphasized their speed of encryption and a wealth of options for dealing with anything that may inhibit the encryption process (i.e., security software). ... process termination, service termination
Researchers said the malware “parses its embedded configuration, kills virtual machines, encrypts files on the infected machine, collects system information, and sends it to the remote server.”
For this phase, DarkSide abuses various tools, namely PowerShell, Metasploit Framework, Mimikatz, and BloodHound... DarkSide aims to gain Domain Controller or Active Directory access.
By targeting virtual machines, ransomware operators can also encrypt multiple servers at once with a single command. In June, researchers spotted a new REvil ransomware Linux encryptor designed to target VMware ESXi virtual machines, a popular enterprise virtual machine platform.
This ransomware group follows the double extortion tactic – meaning not only do they encrypt the user’s data, but also exfiltrate it and threaten to make it public in case the ransom demand is not met.
“Successful data encryption also rose to 56 per cent of attacks” and recovery requires restoring data and systems after ransomware encrypts them.
The latest version of DarkSide attempts to stop the same list of backup and anti-malware services as previous versions targeted | DarkSide kills processes that contain the following strings in their names to unlock the files
The binary uses COM objects and WMI commands to delete volume shadow copies... it deletes each of the shadow copy objects via the DeleteInstance method. | Offset 0x06 Yes Delete volume shadow copies... The process executes the following SQL query “SELECT * FROM Win32_ShadowCopy” ... and then it deletes each of the shadow copy objects via the DeleteInstance method.
146 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware family for which a decryptor was released for early versions only; later variants are not covered.
Ransomware operation associated with the Colonial Pipeline incident and double-extortion tradecraft involving data theft before encryption.
DarkSide is mentioned only as background comparison for how other ransomware operations faced disruption after high-profile attacks.
Ransomware referenced as a former REvil affiliate involved in the Colonial Pipeline attack; mentioned for background and comparison rather than as the main malware in this reference.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.