DarkSide is a ransomware-as-a-service operation and malware family that emerged in 2020 and became one of the most prominent big-game ransomware threats before its public shutdown in 2021. It is best known for the attack on Colonial Pipeline, which triggered major operational disruption and intense law-enforcement scrutiny. DarkSide targeted large private-sector organizations and operated an affiliate model in which core operators supplied the ransomware and extortion infrastructure while partners obtained access to victim networks and deployed the payload.
DarkSide is associated with double-extortion operations in which data theft and public leak pressure accompany file encryption. The malware family includes Windows encryptors and a Linux variant used against enterprise Linux and VMware ESXi environments. Reporting also links DarkSide distribution to access brokers and, in some intrusions, to upstream malware such as Zloader. The group advertised for affiliates and initial access providers on Russian-language cybercrime forums and stated that it avoided systems in Commonwealth of Independent States countries.
Technically, DarkSide is known for fast encryption approaches including partial encryption to accelerate impact on large environments. The operation has been tied to credential theft, reconnaissance, privilege escalation, lateral movement, exfiltration, and broader post-compromise activity typical of human-operated ransomware intrusions. Public reporting and later successor-family analysis indicate substantial continuity between DarkSide and BlackMatter, with BlackMatter widely assessed as a repaint or successor of the DarkSide operation. DarkSide has also been discussed as part of the lineage that informed later ALPHV/BlackCat activity, although direct organizational continuity there is less certain.
DarkSide’s operational history illustrates the industrialized ransomware ecosystem: recruitment of affiliates, collaboration with initial access brokers, selective targeting of high-revenue enterprises, and use of leak sites for extortion. After the Colonial Pipeline incident, DarkSide reported losing control of parts of its infrastructure and funds and subsequently ceased public operations, but its tooling, tradecraft, and personnel were widely believed to have persisted through successor brands.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In others, the CVE-2019-1579 vulnerability in Palo Alto’s GlobalProtect portal and GlobalProtect Gateway interface products and Microsoft Exchange server exposure were used. As a result of exploitation, an unauthenticated attacker could execute malicious code remotely (RCE). | DarkSide ransomware recently attacked the Colonial Pipeline — the largest pipeline in the United States... DarkSide stands out from other ransomware as a service (RaaS) threats, as one of the attack vectors is based on the Zloader botnet (also known as “Silent Night”).
Since initially surfacing in August 2020, the creators of DARKSIDE ransomware and their affiliates have launched a global crime spree affecting organizations in more than 15 countries and multiple industry verticals. | The threat actor obtained initial access to their victim by exploiting CVE-2021-20016, an exploit in the SonicWall SMA100 SSL VPN product, which has been patched by SonicWall. There is some evidence to suggest the threat actor may have used the vulnerability to disable multi-factor authentication options on the SonicWall VPN, although this has not been confirmed.
10 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
FIN7 has attempted to run Darkside ransomware with the filename sleep.exe.
SMOKEDHAM ... a été utilisée par UNC24655, un affilié RaaS précédemment associé aux groupes Lockbit et Darkside.
On Sunday, May 9th Dragos released an intel report to our customers that assessed with high confidence that the DarkSide ransomware group was responsible for the IT compromise.
BlackMatter is linked to the Coreid cyber crime group, which was previously responsible for the Darkside ransomware.
DarkSide is an emerging RaaS (ransomware as a service) criminal group... The DarkSide ransomware virus will check to see if the current user is an administrator when it is first launched.
ELBRUS developed their own RaaS ecosystem named DarkSide. They deployed DarkSide payloads as part of their operations and recruited and managed affiliates that deployed the DarkSide ransomware.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
DarkSide aims to gain Domain Controller (DC) or Active Directory access. This is used to harvest credentials, escalate privileges, and gather valuable assets that will be exfiltrated.
DarkSide aims to gain Domain Controller (DC) or Active Directory access. This is used to harvest credentials, escalate privileges, and gather valuable assets that will be exfiltrated.
Stealth tactics include: ... Obfuscation techniques like encoding and dynamic library loading
To avoid detection by AV and EDR solutions, the ransomware dynamically loads its libraries, without registering them in its imports section
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
DarkSide aims to gain Domain Controller (DC) or Active Directory access. This is used to harvest credentials, escalate privileges, and gather valuable assets that will be exfiltrated.
The malware creates a mutex called “Global\4787658f1cc4202b8a15e05dd0323fde”, which makes sure that there is only one instance of the ransomware running at a time.
By targeting virtual machines, ransomware operators can also encrypt multiple servers at once with a single command. In June, researchers spotted a new REvil ransomware Linux encryptor designed to target VMware ESXi virtual machines, a popular enterprise virtual machine platform.
They emphasized their speed of encryption and a wealth of options for dealing with anything that may inhibit the encryption process (i.e., security software). ... process termination, service termination
Researchers said the malware “parses its embedded configuration, kills virtual machines, encrypts files on the infected machine, collects system information, and sends it to the remote server.”
For this phase, DarkSide abuses various tools, namely PowerShell, Metasploit Framework, Mimikatz, and BloodHound... DarkSide aims to gain Domain Controller or Active Directory access.
By targeting virtual machines, ransomware operators can also encrypt multiple servers at once with a single command. In June, researchers spotted a new REvil ransomware Linux encryptor designed to target VMware ESXi virtual machines, a popular enterprise virtual machine platform.
The operators say that the crypto-locking malware that Darkside provides to affiliates can encrypt both Windows and Linux files. | Ransomware operators provide crypto-locking malware code to third parties. Each affiliate receives a version of code with their unique ID embedded.
The latest version of DarkSide attempts to stop the same list of backup and anti-malware services as previous versions targeted | DarkSide kills processes that contain the following strings in their names to unlock the files
The binary uses COM objects and WMI commands to delete volume shadow copies... it deletes each of the shadow copy objects via the DeleteInstance method. | Offset 0x06 Yes Delete volume shadow copies... The process executes the following SQL query “SELECT * FROM Win32_ShadowCopy” ... and then it deletes each of the shadow copy objects via the DeleteInstance method.
146 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
DarkSide is mentioned only as background comparison for how other ransomware operations faced disruption after high-profile attacks.
Ransomware referenced as a former REvil affiliate involved in the Colonial Pipeline attack; mentioned for background and comparison rather than as the main malware in this reference.
Ransomware operated via an affiliate model. The operators provide crypto-locking malware to affiliates, maintain payment and leak-site infrastructure, target large organizations, can encrypt both Windows and Linux files, and use data theft plus public shaming to pressure victims into paying.
Ransomware family described here as the predecessor/continuation lineage for BlackMatter; the first BlackMatter version was said to be almost identical to the latest DarkSide version.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.