DarkSide is a Russian-speaking ransomware-as-a-service operation that emerged in 2020 and became one of the most prominent double-extortion threats of the early 2020s. The group is best known for the 2021 Colonial Pipeline incident, in which a DarkSide affiliate compromised the company’s IT environment and triggered a major operational shutdown that disrupted fuel distribution across the U.S. East Coast. U.S. officials publicly assessed that the actors were based in Russia, while no conclusive public evidence established direct Russian state control. DarkSide publicly portrayed itself as financially motivated and apolitical, but its operations had significant real-world impact on critical infrastructure. DarkSide operated a structured affiliate model in which core developers supplied ransomware tooling, management infrastructure, and leak-site capabilities to partners who conducted intrusions and deployed the payload. Reporting has linked the ecosystem to multiple affiliate or intrusion clusters, including activity tracked as UNC2628, UNC2659, and UNC2465. The operation used double extortion, stealing data before encryption and threatening publication if victims refused to pay. Public reporting from 2021 associated DarkSide with at least dozens of known extortion cases. Victimology included enterprises in the United States and Europe, with observed impacts in energy and other sectors. DarkSide claimed to avoid certain targets, including organizations in former Soviet states and some sectors tied to public welfare, but the affiliate model limited centralized control over target selection and consequences. After the Colonial Pipeline attack, the group stated it would more carefully moderate affiliate targeting because of the social fallout. Observed tradecraft included credential-based initial access, including use of stolen VPN credentials, phishing-derived access, and in some cases exploitation of perimeter devices. Affiliates and associated actors used brute force and password-spraying against remote access services, exploited vulnerabilities such as CVE-2021-20016 in SonicWall SMA appliances, and leveraged remote administration tools and native utilities for persistence and lateral movement. Reported post-compromise activity included use of PSExec, RDP, SSH, TeamViewer, Cobalt Strike, and SystemBC, along with data exfiltration to cloud storage services. Dwell times varied by intrusion cluster, ranging from rapid deployment within days to multiweek persistence before encryption. The malware supported both Windows and Linux environments, including virtualization-focused targeting on Linux and VMware ESXi-related systems. Reported behaviors included privilege escalation via CMSTPLUA, deletion of Volume Shadow Copies, termination of backup and database services, attempts to tamper with security tooling, and encryption of virtual disk files in Linux environments. These capabilities made DarkSide particularly disruptive in enterprise environments with mixed Windows and virtualized infrastructure. DarkSide is widely assessed as part of a lineage that later rebranded under BlackMatter and subsequently ALPHV/BlackCat after intense law-enforcement and political pressure following Colonial Pipeline. Security reporting has also associated individual affiliates such as Mikhail Matveev, also known as Wazawaka, with DarkSide activity. The group’s prominence, mature affiliate structure, and role in a landmark critical-infrastructure incident made DarkSide a defining ransomware actor of its period.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
44 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
18 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware group responsible for the Colonial Pipeline incident, demonstrating disruptive impact on critical infrastructure.
Referenced as the ransomware group behind the Colonial Pipeline incident, used here as an example of OT/IT risk assessment gaps rather than the main subject.
Referenced as the ransomware group whose Colonial Pipeline attack prompted XSS to ban overt ransomware-related forum activity.
Referenced as the ransomware group associated with the Colonial Pipeline attack; the content notes Telegram channels bearing its name were among sources contributing exposed credential records.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.