Darkpower (also tracked as Dark Power) is a ransomware operator no longer publishing new disclosures. Darkfield has indexed 10 public victims claimed by this operator between March 11, 2023. Darkpower is a relatively obscure ransomware group that emerged in March 2023, operating with apparent financial motivations based on their targeting patterns and ransom demands. The group's origin and potential state affiliations remain unclear due to limited public documentation by major threat intelligence organizations, though their diverse geographic targeting across Turkey, Czech Republic, France, Peru, and Algeria suggests either opportunistic selection or a broad operational scope. With only 10 documented victims since their emergence, Darkpower appears to be a smaller-scale operation that has specifically focused on healthcare sector organizations, potentially indicating either specialized capabilities for compromising medical infrastructure or opportunistic targeting of organizations perceived as more likely to pay ransoms quickly due to operational criticality. The group's specific attack methodologies, initial access vectors, and technical capabilities have not been extensively documented in public threat intelligence reports from major security firms or government agencies. Given the limited public information available and the relatively small victim count, Darkpower's current operational status remains unclear, though the group has not been subject to any publicized law enforcement actions or confirmed disruptions as of late 2023.
How we know this. Operator profiles on Darkfield are built from continuous monitoring of every leak site the group is known to operate, cross-correlated with community-curated feeds (RansomLook, ransomware.live, RansomWatch, MISP-galaxy). Status flips from active to inactive when no new disclosure appears for 60 days. MITRE ATT&CK mappings shown in the interactive section below are sourced from CISA, vendor analysis, and the MITRE community catalog — we attribute each technique back to its source. Aliases reflect operator re-brands and affiliate splits.