Ransomware Group:  
Darkside



Sponsored by Hudson RockUse Hudson Rock's free cybercrime intelligence tools to learn how compromised credentials are impacting your business


Sites | External Information | Tools | Negotiations | Ransom Note(s) | Activity | Victims (10)

Darkside ransomware group has started its operation in August of 2020 with the model of RaaS (Ransomware-as-a-Service). They have become known for their operations of large ransoms scale. They have announced that they prefer not to attack hospitals, schools, non-profits, and governments, but rather big organizations that can be able to pay large ransoms. Darkside ransomware group became very famous following the cyberattack of the Colonial Pipeline and Toshiba unit. The FBI finally terminate the Darkside operation and Managed to pull money from their wallets back.


Sites

Title Available Last Visit FQDN Screenshot
None 🔴 2021-05-01 00:00:00.000000 darksidc3iux462n6yunevoag52ntvwp6wulaz3zirkmh4cnz6hhj7id.onion N/A

External information

Tools used

Discovery RMM Tools Defense Evasion Credential Theft OffSec Networking LOLBAS Exfiltration
ADRecon AnyDesk Mimikatz Cobalt Strike Plink PsExec Bashupload
AdFind GoToAssist SessionGopher CrackMapExec MEGA
Advanced IP Scanner TightVNC Impacket pCloud
SoftPerfect NetScan PowerSploit RClone
Sendspace

This information is provided by Ransomware-Tool-Matrix

 Negotiation chats

Name # Msg Initial Ransom Negotiated Ransom Paid
20201115 243 $1,000,000 $350,000 💸
20210413 63 $600,000 $250,000 💸
20210418 10 N/A N/A
20210215 24 N/A $250,000 💸
20200811 85 N/A N/A

This information is provided by Valéry Marchive

Ransom Note(s)

Activity over time

10 Victims

GB flag

One Call (insurance)

Company logo


Discovery Date: 2021-05-13 00:00

Sector: Financial Services

US flag

Colonial Pipeline

Company logo


Discovery Date: 2021-05-07 00:00

Sector: Transportation Systems

 flag

Toshiba Tec Group

Company logo


Discovery Date: 2021-05-01 00:00

Sector: Critical Manufacturing

 flag

Compucom (MSP)

Company logo


Discovery Date: 2021-02-27 00:00

Sector: Information Technology

CA flag

Discount Car and Truck Rentals

Company logo


Discovery Date: 2021-02-01 00:00

Sector: Transportation Systems

IT flag

Segafredo Zanetti

Company logo


Discovery Date: 2021-02-01 00:00

Sector: Food and Agriculture

BR flag

Companhia Paranaense de Energia (Copel)

Company logo


Discovery Date: 2021-02-01 00:00

Sector: Energy

CA flag

Home Hardware Stores Ltd

Company logo


Discovery Date: 2021-02-01 00:00

Sector: Commercial Facilities

 flag

Guess

Company logo


Discovery Date: 2021-02-01 00:00

Sector: Commercial Facilities

 flag

Brookfield Residential (land developer and home builder)

Company logo


Discovery Date: 2020-08-01 00:00

Sector: Commercial Facilities