Ransomware Group:  
Darkside



Sponsored by Hudson RockUse Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business


Sites | External Information | Tools | Negotiations | Ransom Note(s) | Activity | Worldmap | Victims (10)

Darkside ransomware group has started its operation in August of 2020 with the model of RaaS (Ransomware-as-a-Service). They have become known for their operations of large ransoms scale. They have announced that they prefer not to attack hospitals, schools, non-profits, and governments, but rather big organizations that can be able to pay large ransoms. Darkside ransomware group became very famous following the cyberattack of the Colonial Pipeline and Toshiba unit. The FBI finally terminate the Darkside operation and Managed to pull money from their wallets back.


Sites

Title Available Last Visit FQDN Screenshot
None 🔴 2021-05-01 00:00:00.000000 darksidc3iux462n6yunevoag52ntvwp6wulaz3zirkmh4cnz6hhj7id.onion N/A

External information

Tools used

Discovery RMM Tools Defense Evasion Credential Theft OffSec Networking LOLBAS Exfiltration
ADRecon AnyDesk Mimikatz Cobalt Strike Plink PsExec Bashupload
AdFind GoToAssist SessionGopher CrackMapExec MEGA
Advanced IP Scanner TightVNC Impacket pCloud
SoftPerfect NetScan PowerSploit RClone
Sendspace

This information is provided by Ransomware-Tool-Matrix

 Negotiation chats

Name # Msg Initial Ransom Negotiated Ransom Paid
20201115 243 $1,000,000 $350,000
20210413 63 $600,000 $250,000
20210418 10 N/A N/A
20210215 24 N/A $250,000
20200811 85 N/A N/A

This information is provided by Valéry Marchive & Julien Mousqueton

Ransom Note(s)

Activity over time

Worldmap

10 Victims

GB flag

One Call (insurance) 

Company logo
Ransomware Group:

Discovery Date: 2021-05-13 00:00

Group: 
US flag

Colonial Pipeline 

Company logo
Ransomware Group:

Discovery Date: 2021-05-07 00:00

Group: 
 flag

Toshiba Tec Group 

Company logo
Ransomware Group:

Discovery Date: 2021-05-01 00:00

Group: 
 flag

Compucom (MSP) 

Company logo
Ransomware Group:

Discovery Date: 2021-02-27 00:00

Group: 
CA flag

Discount Car and Truck Rentals  

Company logo
Ransomware Group:

Discovery Date: 2021-02-01 00:00

Group: 
IT flag

Segafredo Zanetti 

Company logo
Ransomware Group:

Discovery Date: 2021-02-01 00:00

Group: 
BR flag

Companhia Paranaense de Energia (Copel) 

Company logo
Ransomware Group:

Discovery Date: 2021-02-01 00:00

Sector: Energy

Group: 
CA flag

Home Hardware Stores Ltd 

Company logo
Ransomware Group:

Discovery Date: 2021-02-01 00:00

Group: 
 flag

Guess 

Company logo
Ransomware Group:

Discovery Date: 2021-02-01 00:00

Group: 
 flag

Brookfield Residential (land developer and home builder) 

Company logo
Ransomware Group:

Discovery Date: 2020-08-01 00:00

Group: