DarkBit is a Windows ransomware family and destructive attack persona associated with Iranian state-linked operations, particularly activity attributed to DEV-1084 and linked by multiple reports to MuddyWater, also tracked by Microsoft as Mango Sandstorm. It became publicly known in 2023 during the attack on the Technion Israel Institute of Technology, where the operation was widely assessed as politically motivated and disruptive rather than a conventional profit-driven ransomware campaign. DarkBit has also been described as a front or persona used to mask destructive activity under the appearance of ransomware.
Technically, DarkBit is a 64-bit Windows executable written in Go and protected with obfuscation, including concealed DLL and API names and dynamic API resolution to hinder static analysis and detection. Observed behavior includes mutex-based single-instance control, multithreaded execution, filesystem traversal to identify files for encryption, chunked file processing, appending encrypted key material to affected files, renaming encrypted files with a dedicated extension, and dropping ransom notes in impacted directories. The malware has been observed deleting shadow copies prior to encryption and contains logic consistent with using Windows Restart Manager APIs to handle locked files. Analysis of available samples indicates use of strong symmetric file encryption, while later research showed implementation weaknesses in key generation that enabled development of a decryptor.
Reported intrusion chains tied to DarkBit involved a lure delivered in an ISO image containing a disguised shortcut and archive. The shortcut abused a legitimate Windows utility to unpack and launch a payload identified as a Cobalt Strike beacon, which then retrieved the ransomware stage. This supports assessment that DarkBit was deployed after an initial foothold and post-compromise staging rather than as a simple commodity ransomware drop. The ransom messaging combined extortion claims with overt political themes, including claims of data theft and threats to leak stolen information, reinforcing the assessment that DarkBit served both disruptive and psychological objectives in operations aligned with Iranian geopolitical interests.
DarkBit primarily targets Windows environments and has been associated with attacks against Israeli organizations and broader disruptive operations attributed to Iranian threat actors. Its significance lies not only in its encryption capability but also in its role as a state-linked ransomware facade blending espionage tradecraft, destructive intent, and information operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Recently, we came across a tweet about DarkBit ransomware. An Iranian APT group, named MuddyWater, is reportedly behind the DarkBit ransomware.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
Further analysis revealed that they had obfuscated some dll names like advapi32.dll and functions like SystemFunction036... Its dynamically resolving API at this address. Malware authors tend to dynamically resolve API to avoid static detections.
"names": { "thumbs.db": 1, "desktop.ini": 1, "darkbit.jpg": 1, "recovery_darkbit.txt": 1, "system volume information": 1 }
As the customary prelude to file encryption, they are using vssadmin.exe to delete all the shadow copies.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware persona/family linked to disruptive operations attributed to MuddyWater.
Ransomware whose encryption has been cracked by researchers, potentially allowing victims to recover files without paying ransom.
Ransomware that encrypts files and demands payment, known for a weak key generation algorithm. Believed to be associated with the MuddyWater Iranian espionage group.
Named malware/tool referenced as an alternate name associated with Storm-1084 in Microsoft's naming table.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.