darkside
Group profile
Darkside ransomware group has started its operation in August of 2020 with the model of RaaS (Ransomware-as-a-Service). They have become known for their operations of large ransoms scale. They have announced that they prefer not to attack hospitals, schools, non-profits, and governments, but rather big organizations that can be able to pay large ransoms. Darkside ransomware group became very famous following the cyberattack of the Colonial Pipeline and Toshiba unit. The FBI finally terminate the Darkside operation and Managed to pull money from their wallets back.
MITRE ATT&CK TTPs
Initial Access
T1078Valid Accounts
DarkSide purchased access from initial access brokers and used compromised RDP/VPN credentials to authenticate to victim environments. The Colonial Pipeline attack used a compromised VPN account with no MFA.
T1190Exploit Public-Facing Application
Exploitation of vulnerabilities in internet-facing systems including VPN appliances to gain initial footholds.
Execution
Privilege Escalation
T1068Exploitation for Privilege Escalation
Local privilege escalation exploits used to gain SYSTEM-level access on compromised hosts.
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
T1560.001Archive Collected Data: Archive via Utility
7-Zip used to compress stolen data prior to exfiltration.
Exfiltration
T1567.002Exfiltration Over Web Service: Exfiltration to Cloud Storage
Rclone used to exfiltrate stolen data to cloud storage for double extortion via the DarkSide leak site.
Command and Control
Impact
T1486Data Encrypted for Impact
DarkSide uses Salsa20 for file encryption with RSA-1024 for key protection. Partial file encryption for large files. Skips CIS-region machines based on language check. Best known for the Colonial Pipeline attack (May 2021) causing fuel supply disruption across US East Coast. Predecessor to BlackMatter.
T1489Service Stop
Over 400 Windows services and 40+ processes terminated before encryption to maximize file access.
T1490Inhibit System Recovery
Shadow copies deleted via vssadmin and wmic; Windows recovery mode disabled via bcdedit.
Recent victims
| Date | Website / victim | Sector | Country |
|---|---|---|---|
| 2021-05-13 | O One Call (insurance) | Manufacturing | GB |
| 2021-05-07 | Colonial Pipelinecolonialpipeline.com | Transportation/Logistics | US |
| 2021-05-01 | T Toshiba Tec Group | Manufacturing | |
| 2021-02-27 | C Compucom (MSP) | Business Services | |
| 2021-02-01 | C Companhia Paranaense de Energia (Copel) | Energy | BR |
| 2021-02-01 | D Discount Car and Truck Rentals | Transportation/Logistics | CA |
| 2021-02-01 | S Segafredo Zanetti | Agriculture and Food Production | IT |
| 2021-02-01 | G Guess | Consumer Services | |
| 2021-02-01 | H Home Hardware Stores Ltd | Consumer Services | CA |
| 2020-08-01 | B Brookfield Residential (land developer and home builder) | Construction |

