Skip to main content

Operator dossier

darkside (also tracked as BlackMatter) is a ransomware operator no longer publishing new disclosures. Darkfield has indexed 10 public victims claimed by this operator between August 1, 2020 and May 13, 2021. DarkSide is a financially motivated ransomware group that emerged in August 2020, quickly gaining notoriety for its professional operational structure and targeted attacks against high-value organizations. The group is widely assessed by Mandiant, CISA, and the FBI to be based in Russia or a Russian-speaking country, and operated as a Ransomware-as-a-Service (RaaS) platform, recruiting affiliates to conduct intrusions while the core group maintained the malware infrastructure and negotiation portals. DarkSide primarily gained initial access through compromised Remote Desktop Protocol (RDP) credentials, phishing, and exploitation of vulnerable internet-facing systems, subsequently deploying tools such as Cobalt Strike and Mimikatz for lateral movement and credential harvesting before exfiltrating sensitive data and encrypting victim systems in a double extortion scheme. The group's most significant and publicly documented campaign was the May 2021 attack against Colonial Pipeline, a critical U.S. fuel pipeline operator, which caused widespread fuel supply disruptions across the U.S. East Coast, prompted a CISA and FBI joint advisory, and resulted in a ransom payment of approximately 4.4 million USD, of which the U.S. Department of Justice subsequently recovered roughly 2.3 million USD. Following the Colonial Pipeline attack and the significant law enforcement and geopolitical pressure it generated, DarkSide announced it was shutting down operations in May 2021, citing pressure from an unspecified third party, though security researchers including Mandiant assessed that the group likely rebranded as BlackMatter shortly thereafter before that successor group also ceased operations in late 2021.

Most-affected countries

How we know this. Operator profiles on Darkfield are built from continuous monitoring of every leak site the group is known to operate, cross-correlated with community-curated feeds (RansomLook, ransomware.live, RansomWatch, MISP-galaxy). Status flips from active to inactive when no new disclosure appears for 60 days. MITRE ATT&CK mappings shown in the interactive section below are sourced from CISA, vendor analysis, and the MITRE community catalog — we attribute each technique back to its source. Aliases reflect operator re-brands and affiliate splits.

Inactive ransomware operator

All groups

darkside

aka BlackMatter · 10 victims indexed · first seen 6 years ago · last activity 5 years ago

10
Victims indexed
#215 of 370 tracked operators
9m
Active period
Aug 2020 → May 2021
5
Countries hit
top CA · 2

At a glance

Status
inactive
Aliases
BlackMatter
First seen
6 years ago
Last activity
5 years ago
Onion sites
1 known endpoint
Primary sector
Transportation/Logistics · 2 hits

About

DarkSide is a financially motivated ransomware group that emerged in August 2020, quickly gaining notoriety for its professional operational structure and targeted attacks against high-value organizations. The group is widely assessed by Mandiant, CISA, and the FBI to be based in Russia or a Russian-speaking country, and operated as a Ransomware-as-a-Service (RaaS) platform, recruiting affiliates to conduct intrusions while the core group maintained the malware infrastructure and negotiation portals. DarkSide primarily gained initial access through compromised Remote Desktop Protocol (RDP) credentials, phishing, and exploitation of vulnerable internet-facing systems, subsequently deploying tools such as Cobalt Strike and Mimikatz for lateral movement and credential harvesting before exfiltrating sensitive data and encrypting victim systems in a double extortion scheme. The group's most significant and publicly documented campaign was the May 2021 attack against Colonial Pipeline, a critical U.S. fuel pipeline operator, which caused widespread fuel supply disruptions across the U.S. East Coast, prompted a CISA and FBI joint advisory, and resulted in a ransom payment of approximately 4.4 million USD, of which the U.S. Department of Justice subsequently recovered roughly 2.3 million USD. Following the Colonial Pipeline attack and the significant law enforcement and geopolitical pressure it generated, DarkSide announced it was shutting down operations in May 2021, citing pressure from an unspecified third party, though security researchers including Mandiant assessed that the group likely rebranded as BlackMatter shortly thereafter before that successor group also ceased operations in late 2021.

References

184 links

External sources curated by the MISP threat-intel community.

Timeline

3 months
2020-08-01T00:00:00+00:00 · 12021-02-01T00:00:00+00:00 · 62021-05-01T00:00:00+00:00 · 3
2020-08-01T00:00:00+00:002021-05-01T00:00:00+00:00

Top countries

🇨🇦 Canada
2
🇧🇷 Brazil
1
🇺🇸 United States
1
🇮🇹 Italy
1
🇬🇧 United Kingdom
1

Top sectors

Transportation/Logistics
2
Manufacturing
2
Consumer Services
2
Agriculture and Food Production
1
Construction
1
Business Services
1
Energy
1

MITRE ATT&CK

28 techniques · 10 tactics

Tactics

Initial AccessExecutionPrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationImpact

Techniques

  • T1190Exploit Public-Facing Application
  • T1133External Remote Services
  • T1078Valid Accounts
  • T1059.001Command and Scripting Interpreter: PowerShell
  • T1059.003Command and Scripting Interpreter: Windows Command Shell
  • T1053.005Scheduled Task/Job: Scheduled Task
  • T1548.002Abuse Elevation Control Mechanism: Bypass User Account Control
  • T1055Process Injection
  • T1112Modify Registry
  • T1562.001Impair Defenses: Disable or Modify Tools
  • T1070.004Indicator Removal: File Deletion
  • T1027Obfuscated Files or Information
  • T1003.001OS Credential Dumping: LSASS Memory
  • T1021.001Remote Services: Remote Desktop Protocol
  • T1021.002Remote Services: SMB/Windows Admin Shares
  • T1570Lateral Tool Transfer
  • T1083File and Directory Discovery
  • T1082System Information Discovery
  • T1018Remote System Discovery
  • T1135Network Share Discovery
  • T1005Data from Local System
  • T1039Data from Network Shared Drive
  • T1041Exfiltration Over C2 Channel
  • T1567.002Exfiltration Over Web Service: Exfiltration to Cloud Storage
  • T1486Data Encrypted for Impact
  • T1490Inhibit System Recovery
  • T1489Service Stop
  • T1491.001Defacement: Internal Defacement

Detection · YARA rules

2 rules
  • RANSOM_Darkside

    YARA rule from ATR/Trellix: ransomware/RANSOM_Darkside.yar

    source: ATR/Trellix

  • RANSOM_Darkside_DLL_May2021

    YARA rule from ATR/Trellix: ransomware/RANSOM_Darkside.yar

    source: ATR/Trellix

Recent victims

Loading…

Onion infrastructure

1 known
  • http://darksidc3iux462n6yunevoag52ntvwp6wulaz3zirkmh4cnz6hhj7id.onion

Source

Updated 5 years ago

Data on this page is sourced from the group's own leak posts, cross-checked with public ransomware trackers (RansomLook, ransomware.live, RansomWatch), MITRE ATT&CK, and our own Tor and Telegram crawlers. This is a public observatory page — share freely.

Get alerted the next time darkside posts a victim.

Add darkside to your watchlist — Pro pings you within 5 minutes of any new darkside leak-site post, Telegram callout, or affiliate-rebrand inference.