Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Darkside

Darkside ransomware group has started its operation in August of 2020 with the model of RaaS (Ransomware-as-a-Service). They have become known for their operations of large ransoms scale. They have announced that they prefer not to attack hospitals, schools, non-profits, and governments, but rather big organizations that can be able to pay large ransoms. Darkside ransomware group became very famous following the cyberattack of the Colonial Pipeline and Toshiba unit. The FBI finally terminate the Darkside operation and Managed to pull money from their wallets back.
External information

Victims
 

10

First Discovered
victim

2020-08-01

Last Discovered
victim

2021-05-13

Avg Delay
between attack and claim

N/A

Infostealer
for victim with domain

N/A

View Victims on World Map


Known Locations (1)
Favicon Title Type Available Last Visit FQDN
favicon None No 2025-06-01 21:18:32 darksidc3iux462n6yunevoag52ntvwp6wulaz3zirkmh4cnz6hhj7id.onion

Target (Available)
Top 5 Activity Sectors
  • Commercial Facilities 3
  • Transportation Systems 2
  • Food and Agriculture 1
  • Energy 1
  • Information Technology 1
Top 5 Countries
  • CA flag Canada 2
  • IT flag Italy 1
  • BR flag Brazil 1
  • US flag United States 1
  • GB flag United Kingdom 1

Heatmap (Available)

Ransom Notes (1)

Tools Used (Available)
This information is provided by Ransomware-Tool-Matrix
Discovery RMM Tools Defense Evasion Credential Theft OffSec Networking LOLBAS Exfiltration
ADRecon

AdFind

Advanced IP Scanner

SoftPerfect NetScan

AnyDesk

GoToAssist

TightVNC






Mimikatz

SessionGopher



Cobalt Strike

CrackMapExec

Impacket

PowerSploit

Plink




PsExec




Bashupload

MEGA

pCloud

RClone

Sendspace

Vulnerabilities Exploited (0)

No vulnerabilities exploited available.


TTPs Matrix (0)

No TTPs available.


Negotiation Chats (5)
20200811 85 msgs
20201115 243 msgs
20210215 24 msgs
20210413 63 msgs
20210418 10 msgs

YARA Rules (1)

Indicators of Compromise (IoCs) (0)

No IoCs available for this group.


Victims (10)
Logo
One Call (insurance) Darkside
Discovery Date: 2021-05-13
N/A
GB
Logo
Colonial Pipeline Darkside
Discovery Date: 2021-05-07
N/A
US
Logo
Toshiba Tec Group Darkside
Discovery Date: 2021-05-01
N/A
Logo
Compucom (MSP) Darkside
Discovery Date: 2021-02-27
N/A
Logo
Discount Car and Truck Rentals Darkside
Discovery Date: 2021-02-01
N/A
CA
Logo
Segafredo Zanetti Darkside
Discovery Date: 2021-02-01
N/A
IT
Logo
Home Hardware Stores Ltd Darkside
Discovery Date: 2021-02-01
N/A
CA
Logo
Guess Darkside
Discovery Date: 2021-02-01
N/A