DarkSide is a ransomware-as-a-service operation that emerged in 2020 and became widely known for the 2021 Colonial Pipeline incident. It operated through a core developer team and affiliates, with the operators providing ransomware tooling and management infrastructure while affiliates conducted intrusions and deployments. DarkSide is associated with financially motivated double-extortion activity in which victim data is stolen before encryption and later used to pressure payment through threatened publication. Public reporting has linked the operation to dozens of intrusions and to targeting of enterprises in sectors including energy and other large organizations, with especially high-profile impact on critical infrastructure through the Colonial Pipeline disruption.
DarkSide intrusions have been associated with multiple initial access methods depending on the affiliate, including use of stolen or phished credentials, credential-based VPN access, brute-force activity, exploitation of CVE-2021-20016 on SonicWall SMA100 appliances, and phishing-delivered backdoor access. Once inside a network, affiliates have been observed maintaining dwell time ranging from a few days to several weeks, conducting reconnaissance, exfiltrating data, and moving laterally with administrative protocols and remote access mechanisms such as RDP, SSH, and PSExec. Reported affiliate tradecraft also included persistence through remote administration software and use of commodity or dual-use tooling such as Cobalt Strike and SystemBC.
The malware supports both Windows and Linux environments. The Windows variant encrypts files, attempts privilege escalation via the CMSTPLUA technique when needed, terminates backup, mail, and database-related services to maximize impact, tampers with security tooling, and deletes Volume Shadow Copies to inhibit recovery. The Linux variant is an ELF payload that has been reported targeting VMware virtualized environments by encrypting VMDK files on ESXi systems. DarkSide’s operational model and technical behavior place it among the more mature ransomware families of its period, combining enterprise-focused intrusion tradecraft with extortion infrastructure and affiliate management.
DarkSide publicly claimed to be apolitical and profit-driven and stated that it avoided certain victim categories, but its affiliate model limited centralized control over target selection and operational consequences. The operation is widely assessed as part of the Russian-speaking cybercriminal ecosystem, though publicly available information does not establish it as a state-directed capability. The group became defunct after intense law-enforcement and public scrutiny following Colonial Pipeline, including a U.S. Department of Justice seizure of part of the ransom proceeds.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Since initially surfacing in August 2020, the creators of DARKSIDE ransomware and their affiliates have launched a global crime spree affecting organizations in more than 15 countries and multiple industry verticals. | The threat actor obtained initial access to their victim by exploiting CVE-2021-20016, an exploit in the SonicWall SMA100 SSL VPN product, which has been patched by SonicWall. There is some evidence to suggest the threat actor may have used the vulnerability to disable multi-factor authentication options on the SonicWall VPN, although this has not been confirmed.
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In 2023, FIN7 expanded its operations to include the deployment of ransomware through affiliations with RaaS groups such as REvil and Maze, while also managing its own RaaS programs, including the now-retired Darkside and BlackMatter.
ELBRUS developed their own RaaS ecosystem named DarkSide. They deployed DarkSide payloads as part of their operations and recruited and managed affiliates that deployed the DarkSide ransomware.
FireEye researchers documented five separate clusters of activity suspected of being connected to DarkSide, the Ransomware-as-a-Service (RaaS) network responsible for the Colonial Pipeline security incident.
FireEye researchers documented five separate clusters of activity suspected of being connected to DarkSide, the Ransomware-as-a-Service (RaaS) network responsible for the Colonial Pipeline security incident.
FireEye researchers documented five separate clusters of activity suspected of being connected to DarkSide, the Ransomware-as-a-Service (RaaS) network responsible for the Colonial Pipeline security incident.
The attack began when a hacker group identified as DarkSide accessed the Colonial Pipeline network. The attackers stole 100 gigabytes of data within a two-hour window. Following the data theft, the attackers infected the Colonial Pipeline IT network with ransomware that affected many computer systems, including billing and accounting.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
In Sophos’ experience in data forensics and incident response to DarkSide attacks, the initial access to the target’s network came primarily as a result of phished credentials.
If it does not, the malware attempts to elevate its privileges using the CMSTPLUA technique.
In Sophos’ experience in data forensics and incident response to DarkSide attacks, the initial access to the target’s network came primarily as a result of phished credentials.
Like other ransomware, DarkSide also deletes Volume Shadow Copies, which could help recover some of the encrypted data if left unmolested.
Using PSExec, Remote Desktop connections, and (in the case of Linux servers) SSH to move laterally within the network...
Using PSExec, Remote Desktop connections, and (in the case of Linux servers) SSH to move laterally within the network...
Wazawaka seems to have adopted the uniquely communitarian view that when organizations being held for ransom decline to cooperate or pay up, any data stolen from the victim should be published on the Russian cybercrime forums for all to plunder.
...the company did pay as it sought to retrieve the stolen information.
DarkSide follows in the footsteps of double-extortion ransomware operators such as REvil, Maze, and LockBit—exfiltrating business data before encrypting it, and threatening public release if the victims don’t pay for a decryption key.
63 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
77 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware family/group associated in the content with the Colonial Pipeline incident.
Ransomware referenced as the malware used in the Colonial Pipeline incident, affecting IT billing systems rather than OT directly.
Ransomware family referenced as the operator behind the Colonial Pipeline attack; mentioned to explain why XSS.is banned overt ransomware-related forum activity.
A named ransomware operation/group referenced in connection with Telegram channels linked to exposed credential records.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.