d4rk4rmy is a ransomware operator no longer publishing new disclosures. Darkfield has indexed 18 public victims claimed by this operator between July 7, 2025 and August 16, 2025. d4rk4rmy is a recently emerged ransomware group that was first observed in July 2025, operating with apparent financial motivations based on their targeting of high-value sectors including financial services and technology organizations. With only 18 documented victims to date, the group appears to be in its early operational phase, demonstrating a geographically diverse targeting approach across the United States, Taiwan, Brazil, Poland, and Monaco, with particular focus on financially lucrative sectors such as financial services, technology, transportation and logistics, and hospitality and tourism industries. Given the group's recent emergence and limited public documentation from established threat intelligence sources, specific details regarding their country of origin, operational structure, attack methodologies, encryption techniques, and whether they operate as a Ransomware-as-a-Service model remain largely undetermined by major cybersecurity organizations such as CISA, FBI, or prominent security research firms. The group's current operational status appears active based on the recent timeline of their emergence, though comprehensive analysis of their capabilities, notable campaigns, and potential law enforcement actions is limited due to insufficient publicly available intelligence from authoritative sources.
How we know this. Operator profiles on Darkfield are built from continuous monitoring of every leak site the group is known to operate, cross-correlated with community-curated feeds (RansomLook, ransomware.live, RansomWatch, MISP-galaxy). Status flips from active to inactive when no new disclosure appears for 60 days. MITRE ATT&CK mappings shown in the interactive section below are sourced from CISA, vendor analysis, and the MITRE community catalog — we attribute each technique back to its source. Aliases reflect operator re-brands and affiliate splits.