Ransomware Group intelligence
Darkside
InactiveTrack Darkside with 10 published victims and 1 known leak locations in a single intelligence view.
Overview
Darkside is tracked by Breach House as a ransomware group with 10 published victims.
Canada is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Down checked 1h ago | darksidc3iux462n6yunevoag52ntvwp6wulaz3zirkmh4cnz6hhj7id.onion |
Top Activity Sectors (5)
Typical Attacks (12)
▼MITRE ATT&CK does not currently catalogue Darkside, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: Darkside executes PowerShell scripts to stage payloads and manipulate system processes during initial compromise.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1569.002 Service Execution Execution
What they do: Darkside executes malicious binaries through service execution mechanisms to maintain persistence and spread.
What that means: Adversaries may abuse the Windows service control manager to execute malicious commands or payloads.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: Darkside disables or modifies security tools like antivirus software to evade detection during ransomware deployment.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: Darkside encrypts or encodes victim files with custom ransomware payloads to ensure irreversible impact.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1070.004 File Deletion Stealth
What they do: Darkside deletes Volume Shadow Copies and backup files via system commands to prevent data recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1003.001 LSASS Memory Credential Access
What they do: Darkside accesses LSASS memory to steal credentials for privilege escalation and lateral movement.
What that means: Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS).
-
T1110 Brute Force Credential Access
What they do: Darkside performs brute force attacks against local accounts to gain initial access and persistence footholds.
What that means: Adversaries may use brute force techniques to gain access to accounts when passwords are unknown or when password hashes are obtained.
-
T1057 Process Discovery Discovery
What they do: Darkside uses process discovery to identify critical system processes for targeting during lateral movement and evasion.
What that means: Adversaries may attempt to get information about running processes on a system.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: Darkside exploits SMB/Windows Admin Shares to move laterally across victim networks and encrypt shared data.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: Darkside encrypts victim files for impact using strong symmetric encryption to render data inaccessible.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: Darkside calls system recovery inhibitors to block restore mechanisms and maximize operational disruption.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
-
T1491.001 Internal Defacement Impact
What they do: Darkside performs internal defacement by replacing victim files with ransom notes and altered content.
What that means: An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems.
Tools Observed (20)
▼Software Darkside has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Credential theft
Discovery & enumeration
Exfiltration
LOLBAS (living-off-the-land binaries)
Networking & tunnelling
Offensive security tooling
Remote monitoring & management
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Crypto Wallets (3)
▼| Address | Chain | Received (USD) | Payments |
|---|---|---|---|
bc1qhq37atw5ldcppf2fd0fsmsmejxkvp2qfy472pq |
bitcoin | $4,451,309 | 1 |
bc1q7eqww9dmm9p48hx5yz5gcvmncu65w43wfytpsf |
bitcoin | $4,410,283 | 2 |
bc1qjhdw0582hu8sl2l56dyu9l4rk366hhu7j5xpgu |
bitcoin | $249,725 | 1 |
Crowdsourced payment data from Ransomwhere, licensed CC BY 4.0. Figures are what has been reported and attributed to this family, not a confirmed total. Cite as: Cable, Jack. (2024). Ransomwhere: A Crowdsourced Ransomware Payment Dataset (1.1.0) [Data set]. Zenodo. https://doi.org/10.5281/zenodo.6512122
Ransom Notes (1)
▼The note this group leaves on a compromised machine. Click a filename to read it.
darkside.txt
----------- [ Welcome to DarkSide ] -------------> What happend? ---------------------------------------------- Your computers and servers are encrypted, backups are deleted. We use strong encryption algorithms, so you cannot decrypt your data. But you can restore everything by purchasing a special program from us - universal decryptor. This program will restore all your network. Follow our instructions below and you will recover all your data. What guarantees? ---------------------------------------------- We value our reputation. If we do not do our work and liabilities, nobody will pay us. This is not in our interests. All our decryption software is perfectly tested and will decrypt your data. We will also provide support in case of problems. We guarantee to decrypt one file for free. Go to the site and contact us. How to get access on website? ---------------------------------------------- Using a TOR browser: 1) Download and install TOR browser from this site: https://torproject.org/ 2) Open our website: http://dark24zz36xm4y2phwe7yvnkkkkhxionhfrwp67awpb3r3bdcneivoqd.onion/ZWQHXVE7MW9JXE5N1EGIP6IMEFAGC7LNN6WJCBVKJFKB5QXP6LUZV654ASG7977V When you open our website, put the following data in the input form: Key: [snip] !!! DANGER !!! DO NOT MODIFY or try to RECOVER any files yourself. We WILL NOT be able to RESTORE them. !!! DANGER !!!
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (10)
Search, filter and paginate the victim timeline for Darkside. Showing 1–10 of 10.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | One Call (insurance) id625 View details | United Kingdom | Finance / Legal / Insurance | — | |
|
No additional victim description available. |
|||||
| Ransomware | Colonial Pipeline id622 View details | United States | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Toshiba Tec Group id614 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Compucom (MSP) id586 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Discount Car and Truck Rentals id564 View details | Canada | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Segafredo Zanetti id569 View details | Italy | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Companhia Paranaense de Energia (Copel) id571 View details | Brazil | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Home Hardware Stores Ltd id572 View details | Canada | Retail / E-commerce | — | |
|
No additional victim description available. |
|||||
| Ransomware | Guess id573 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Brookfield Residential (land developer and home builder) id455 View details | Construction / Real Estate | — | ||
|
No additional victim description available. |
|||||