HOME

TheInfoList



OR:

DarkSide is a
cybercriminal Cybercrime encompasses a wide range of criminal activities that are carried out using digital devices and/or networks. It has been variously defined as "a crime committed on a computer network, especially the Internet"; Cybercriminals may explo ...
hacking group, believed to be based in
Russia Russia, or the Russian Federation, is a country spanning Eastern Europe and North Asia. It is the list of countries and dependencies by area, largest country in the world, and extends across Time in Russia, eleven time zones, sharing Borders ...
, that targets victims using
ransomware Ransomware is a type of malware that Encryption, encrypts the victim's personal data until a ransom is paid. Difficult-to-trace Digital currency, digital currencies such as paysafecard or Bitcoin and other cryptocurrency, cryptocurrencies are com ...
and
extortion Extortion is the practice of obtaining benefit (e.g., money or goods) through coercion. In most jurisdictions it is likely to constitute a criminal offence. Robbery is the simplest and most common form of extortion, although making unfounded ...
; it is believed to be behind the
Colonial Pipeline cyberattack On May 7, 2021, Colonial Pipeline, an American oil pipeline system that originates in Houston, Texas, and carries gasoline and jet fuel mainly to the Southeastern United States, suffered a ransomware cyberattack that afflicted computerized equ ...
.Dustin Volz
U.S. Blames Criminal Group in Colonial Pipeline Hack
''Wall Street Journal'' (May 10, 2021).
Charlie Osborne
Researchers track down five affiliates of DarkSide ransomware service
ZDNet (May 12, 2021).
The group provides ransomware as a service. DarkSide itself claims to be apolitical.


Targets

DarkSide is believed to be based in
Eastern Europe Eastern Europe is a subregion of the Europe, European continent. As a largely ambiguous term, it has a wide range of geopolitical, geographical, ethnic, cultural and socio-economic connotations. Its eastern boundary is marked by the Ural Mountain ...
, likely Russia, but unlike other hacking groups responsible for high-profile cyberattacks it is not believed to be directly state-sponsored (i.e., operated by
Russian intelligence The Foreign Intelligence Service (SVR) is the civilian foreign intelligence agency of Russia. The SVR succeeded the First Chief Directorate of the KGB in December 1991.The Security Organs of the Russian Federation: A Brief History 1991–2004' ...
services).Nicolás Rivero
Hacking collective DarkSide are state-sanctioned pirates
''Quartz'' (May 10, 2021).
DarkSide avoids targets in certain geographic locations by checking their system language settings. In addition to the languages of the 12 current, former, or founding
CIS countries The Commonwealth of Independent States (CIS) is a regional intergovernmental organization in Eurasia. It was formed following the dissolution of the Soviet Union in 1991. It covers an area of and has an estimated population of 246,200,194. ...
the exclusion list contains Syrian Arabic. Experts state that the group is "one of the many for-profit ransomware groups that have proliferated and thrived in Russia" with at least the implicit sanction of the Russian authorities, who allow the activity to occur so long as it attacks foreign targets. The language check feature can be disabled when an instance of ransomware is built. One such version was observed in May 2021. Additionally, DarkSide does not target healthcare centers,
school A school is the educational institution (and, in the case of in-person learning, the Educational architecture, building) designed to provide learning environments for the teaching of students, usually under the direction of teachers. Most co ...
s, and
non-profit organizations A nonprofit organization (NPO), also known as a nonbusiness entity, nonprofit institution, not-for-profit organization, or simply a nonprofit, is a non-governmental (private) legal entity organized and operated for a collective, public, or so ...
. Ransomware code used by DarkSide resembles ransomware software used by
REvil REvil (Ransomware Evil; also known as Sodinokibi) was a Russia-based or Russian-speaking private ransomware-as-a-service (RaaS) operation. After an attack, REvil would threaten to publish the information on their page ''Happy Blog'' unless the ra ...
, a different hacking group; REvil's code is not publicly available, suggesting that DarkSide is an offshoot of REvilDavid E. Sanger & Nicole Perlroth
F.B.I. Identifies Group Behind Pipeline Hack
''New York Times'' (May 10, 2021).
or a partner of REvil. DarkSide and REvil use similarly structured ransom notes and the same code to check that the victim is not located in a
Commonwealth of Independent States The Commonwealth of Independent States (CIS) is a regional organization, regional intergovernmental organization in Eurasia. It was formed following the dissolution of the Soviet Union, dissolution of the Soviet Union in 1991. It covers an ar ...
(CIS) country.What We Know About the DarkSide Ransomware and the US Pipeline Attack
Trend Micro is an American-Japanese cyber security software company. The company has globally dispersed R&D in 16 locations across every continent excluding Antarctica. The company develops enterprise security software for servers, containers, and cloud ...
Research (May 14, 2021).
According to
Trend Micro is an American-Japanese cyber security software company. The company has globally dispersed R&D in 16 locations across every continent excluding Antarctica. The company develops enterprise security software for servers, containers, and cloud ...
Research data, the
United States The United States of America (USA), also known as the United States (U.S.) or America, is a country primarily located in North America. It is a federal republic of 50 U.S. state, states and a federal capital district, Washington, D.C. The 48 ...
is by far DarkSide's most targeted country, at more than 500 detections, followed by
France France, officially the French Republic, is a country located primarily in Western Europe. Overseas France, Its overseas regions and territories include French Guiana in South America, Saint Pierre and Miquelon in the Atlantic Ocean#North Atlan ...
,
Belgium Belgium, officially the Kingdom of Belgium, is a country in Northwestern Europe. Situated in a coastal lowland region known as the Low Countries, it is bordered by the Netherlands to the north, Germany to the east, Luxembourg to the southeas ...
, and
Canada Canada is a country in North America. Its Provinces and territories of Canada, ten provinces and three territories extend from the Atlantic Ocean to the Pacific Ocean and northward into the Arctic Ocean, making it the world's List of coun ...
. Of 25 countries observed by
McAfee McAfee Corp. ( ), formerly known as McAfee Associates, Inc. from 1987 to 1997 and 2004 to 2014, Network Associates Inc. from 1997 to 2004, and Intel Security Group from 2014 to 2017, is an American proprietary software company focused on online ...
the most affected by DarkSide attacks in terms of number of devices impacted per million devices are
Israel Israel, officially the State of Israel, is a country in West Asia. It Borders of Israel, shares borders with Lebanon to the north, Syria to the north-east, Jordan to the east, Egypt to the south-west, and the Mediterranean Sea to the west. Isr ...
(1573.28),
Malaysia Malaysia is a country in Southeast Asia. Featuring the Tanjung Piai, southernmost point of continental Eurasia, it is a federation, federal constitutional monarchy consisting of States and federal territories of Malaysia, 13 states and thre ...
(130.99),
Belgium Belgium, officially the Kingdom of Belgium, is a country in Northwestern Europe. Situated in a coastal lowland region known as the Low Countries, it is bordered by the Netherlands to the north, Germany to the east, Luxembourg to the southeas ...
(106.93),
Chile Chile, officially the Republic of Chile, is a country in western South America. It is the southernmost country in the world and the closest to Antarctica, stretching along a narrow strip of land between the Andes, Andes Mountains and the Paci ...
(103.97),
Italy Italy, officially the Italian Republic, is a country in Southern Europe, Southern and Western Europe, Western Europe. It consists of Italian Peninsula, a peninsula that extends into the Mediterranean Sea, with the Alps on its northern land b ...
(95.91),
Turkey Turkey, officially the Republic of Türkiye, is a country mainly located in Anatolia in West Asia, with a relatively small part called East Thrace in Southeast Europe. It borders the Black Sea to the north; Georgia (country), Georgia, Armen ...
(66.82),
Austria Austria, formally the Republic of Austria, is a landlocked country in Central Europe, lying in the Eastern Alps. It is a federation of nine Federal states of Austria, states, of which the capital Vienna is the List of largest cities in Aust ...
(61.19),
Ukraine Ukraine is a country in Eastern Europe. It is the List of European countries by area, second-largest country in Europe after Russia, which Russia–Ukraine border, borders it to the east and northeast. Ukraine also borders Belarus to the nor ...
(56.09),
Peru Peru, officially the Republic of Peru, is a country in western South America. It is bordered in the north by Ecuador and Colombia, in the east by Brazil, in the southeast by Bolivia, in the south by Chile, and in the south and west by the Pac ...
(26.94), the U.S. (24.67). As of June 2021, DarkSide has only published data from one company; the amount of data published exceeds 200 GB.


Mechanism of attack

The DarkSide ransomware initially bypasses UAC using the CMSTPLUA COM interface. The software then checks the system's location and language to avoid machines in former Soviet countries; the list of languages that are excluded are
Russian Russian(s) may refer to: *Russians (), an ethnic group of the East Slavic peoples, primarily living in Russia and neighboring countries *A citizen of Russia *Russian language, the most widely spoken of the Slavic languages *''The Russians'', a b ...
, Ukrainian, Belarusian, Tajik,
Armenian Armenian may refer to: * Something of, from, or related to Armenia, a country in the South Caucasus region of Eurasia * Armenians, the national people of Armenia, or people of Armenian descent ** Armenian diaspora, Armenian communities around the ...
, Azerbaijani, Georgian, Kazakh, Kyrgyz, Turkmen, Uzbek,
Tatar Tatar may refer to: Peoples * Tatars, an umbrella term for different Turkic ethnic groups bearing the name "Tatar" * Volga Tatars, a people from the Volga-Ural region of western Russia * Crimean Tatars, a people from the Crimea peninsula by the B ...
, Moldovan Romanian, and Syrian Arabic. The software then creates a file named ''LOG..TXT'', which serves as a
log file In computing, logging is the act of keeping a log of events that occur in a computer system, such as problems, errors or broad information on current operations. These events may occur in the operating system or in other software. A message o ...
. The software deletes files in the
recycle bin A recycling bin (or recycle bin) is a container used to hold recyclables before they are taken to recycling centers. Recycling bins exist in various sizes for use inside and outside of homes, offices, and large public facilities. Separate conta ...
one by one, uninstalls certain security and backup software programs, and terminates processes to allow access to user data files. During the encryption process proper, a user ID is generated based on a
MAC address A MAC address (short for medium access control address or media access control address) is a unique identifier assigned to a network interface controller (NIC) for use as a network address in communications within a network segment. This use i ...
and appear appended to filenames, and file data is encrypted with
Salsa20 Salsa20 and the closely related ChaCha are stream ciphers developed by Daniel J. Bernstein. Salsa20, the original cipher, was designed in 2005, then later submitted to the eSTREAM European Union cryptographic validation process by Bernstein. Ch ...
and a randomly generated matrix key (which, encrypted with a hardcoded RSA key, is itself appended to the file). However, the software avoids encrypting certain folders, files, and filetypes. Finally, the ransomware leaves behind a ransom note titled ''README..TXT'', which directs the user to access a site with Tor; this site then prompts the user to verify their identity and to make a payment using
Bitcoin Bitcoin (abbreviation: BTC; Currency symbol, sign: ₿) is the first Decentralized application, decentralized cryptocurrency. Based on a free-market ideology, bitcoin was invented in 2008 when an unknown entity published a white paper under ...
or
Monero Monero (; Abbreviation: XMR) is a cryptocurrency which uses a blockchain with privacy-enhancing technologies to obfuscate transactions to achieve anonymity and fungibility. Observers cannot decipher addresses trading Monero, transaction amount ...
.


Business model

DarkSide uses intermediary hackers 26c3weq ("affiliates").Michael Schwirtz & Nicole Perlroth
DarkSide, Blamed for Gas Pipeline Attack, Says It Is Shutting Down
''New York Times'' (May 14, 2021).
It uses "ransomware-as-a-service"Chris Nuttall
DarkSide's ransomware-as-a-service
''Financial Times'' (May 10, 2021).
Alert (AA21-131A): DarkSide Ransomware: Best Practices for Preventing Business Disruption from Ransomware Attacks
Cybersecurity and Infrastructure Security Agency/Federal Bureau of Investigation (May 11, 2021, last revised May 12, 2021).
— a model in which DarkSide grants its "affiliate" subscribers (who are screened via an interview) access to ransomware developed by DarkSide, in return for giving DarkSide a share of the ransom payments (apparently 25% for ransom payments under US$500,000 and 10% for ransom payments over US$5 million). Affiliates are given access to an administration panel on which they create builds for specific victims. The panel allows some degree of customization for each ransomware build. Cybersecurity firm
Mandiant Mandiant, Inc. is an American cybersecurity firm and a subsidiary of Google. Mandiant received attention in February 2013 when it released a report directly implicating China in cyber espionage. In December 2013, Mandiant was acquired by FireE ...
, a subsidiary of
FireEye Trellix (formerly FireEye and McAfee Enterprise) is a privately held cybersecurity company that was founded in 2022. It provides hardware, software, and services to investigate cybersecurity attacks, protect against malicious software, and ana ...
, has documented five clusters of threat activity that may represent different affiliates of the DarkSide RaaS platform, and has described three of them, referred to as UNC2628, UNC2659, and UNC2465. Some researchers have contended that DarkSide’s business model is comparable to a franchise, meaning that buyers can use DarkSide’s branding in their attacks. Additionally, DarkSide is known to operate with a level of professionalism, as analysts have noted that the hacker group has a press room, mailing list, and victim hotline found on their website.


History and attacks


2020

The group was first noticed in August 2020. Cybersecurity company
Kaspersky Kaspersky Lab (; ) is a Russian multinational cybersecurity and anti-virus provider headquartered in Moscow, Russia, and operated by a holding company in the United Kingdom. It was founded in 1997 by Eugene Kaspersky, Natalya Kaspersky and A ...
described the group as an "enterprise" due to its professional-looking website and attempts to partner with journalists and decryption companies. The group "has publicly stated that they prefer to target organizations that can afford to pay large ransoms instead of hospitals, schools, non-profits, and governments." The group has sought to foster a "
Robin Hood Robin Hood is a legendary noble outlaw, heroic outlaw originally depicted in English folklore and subsequently featured in literature, theatre, and cinema. According to legend, he was a highly skilled archer and swordsman. In some versions o ...
" image, claiming that they donated some of their ransom proceeds to charity. In a darkweb post, the group posted receipts for donations of (then worth ) each to
Children International Children International is a global nonprofit humanitarian organization that helps children break the cycle of poverty. It addresses children’s critical needs through early intervention and regular interaction in community centers. The goal is t ...
and to The Water Project dated to October 13, 2020; Children International stated that it will not keep the money.


2020 to 2021

From December 2020 to May 2021, ransoms demanded by the group ranged from US$200,000 to US$2 million. DarkSide attacked U.S. oil and gas infrastructure on four occasions. DarkSide ransomware hit the IT
managed services Managed services is the practice of outsourcing the responsibility for maintaining, and anticipating need for, a range of processes and functions, ostensibly for the purpose of improved operations and reduced budgetary expenditures through the ...
provider CompuCom in March 2021, costing over US$20 million in restoration expenses; it also attacked Canadian Discount Car and Truck Rentals and Toshiba Tec Corp., a unit of Toshiba Corp. DarkSide extorted money from the German company Brenntag. The cryptocurrency security firm Elliptic stated that a Bitcoin wallet opened by DarkSide in March 2021 had received US$17.5 million from 21 Bitcoin wallets (including the Colonial Pipeline ransom), indicating the number of ransoms received over the course of a few months. Elliptic's analysis showed that in total, Darkside received over $90 million in ransom payments from at least 47 victims. The average ransom payment was $1.9 million.


2021

The
Federal Bureau of Investigation The Federal Bureau of Investigation (FBI) is the domestic Intelligence agency, intelligence and Security agency, security service of the United States and Federal law enforcement in the United States, its principal federal law enforcement ag ...
identified DarkSide as the perpetrator of the Colonial Pipeline ransomware attack, a cyberattack on May 7, 2021, perpetrated by
malicious code Malware (a portmanteau of ''malicious software'')Tahir, R. (2018)A study on malware and malware detection techniques . ''International Journal of Education and Management Engineering'', ''8''(2), 20. is any software intentionally designed to caus ...
, that led to a voluntary shutdown of the main pipeline supplying 45% of fuel to the
East Coast of the United States The East Coast of the United States, also known as the Eastern Seaboard, the Atlantic Coast, and the Atlantic Seaboard, is the region encompassing the coast, coastline where the Eastern United States meets the Atlantic Ocean; it has always pla ...
. The attack was described as the worst cyberattack to date on U.S.
critical infrastructure Critical infrastructure, or critical national infrastructure (CNI) in the UK, describes infrastructure considered essential by governments for the functioning of a society and economy and deserving of special protection for national security. ...
. DarkSide successfully extorted about 75
Bitcoin Bitcoin (abbreviation: BTC; Currency symbol, sign: ₿) is the first Decentralized application, decentralized cryptocurrency. Based on a free-market ideology, bitcoin was invented in 2008 when an unknown entity published a white paper under ...
(almost US$5 million) from Colonial Pipeline. U.S. officials are investigating whether the attack was purely criminal or took place with the involvement of the Russian government or another state sponsor. Following the attack, DarkSide posted a statement claiming that "We are apolitical, we do not participate in geopolitics...Our goal is to make money and not creating problems for society." In May 2021, the FBI and
Cybersecurity and Infrastructure Security Agency The Cybersecurity and Infrastructure Security Agency (CISA) is a component of the United States Department of Homeland Security (DHS) responsible for cybersecurity and infrastructure protection across all levels of government, coordinating cyber ...
issued a joint alert urging the owners and operators of critical infrastructure to take certain steps to reduce their vulnerability to DarkSide ransomware and ransomware in general. On 14 May 2021, in a Russian-language statement obtained by the cybersecurity firms
Recorded Future Recorded Future, Inc. is an American cybersecurity company founded in 2009, with headquarters in Somerville, Massachusetts. The company was acquired by MasterCard in 2024. History In 2007, co-founders Christopher Ahlberg and Staffan Truvé, bo ...
, FireEye, and Intel 471 and reported by the ''Wall Street Journal'' and ''The New York Times'', DarkSide said that "due to the pressure from the U.S." it was shutting down operations, closing the gang's "affiliate program" (the intermediary hackers that DarkSide works with to hack).Robert McMillan & Dustin Volz
Colonial Pipeline Hacker DarkSide Says It Will Shut Operations
''Wall Street Journal'' (May 14, 2021).
The specific "pressure" referred to was not clear, but the preceding day, U.S. President
Joe Biden Joseph Robinette Biden Jr. (born November 20, 1942) is an American politician who was the 46th president of the United States from 2021 to 2025. A member of the Democratic Party (United States), Democratic Party, he served as the 47th vice p ...
suggested that the U.S. would take action against DarkSide to "disrupt their ability to operate." DarkSide claimed that it had lost access to its payment server, blog, and funds withdrawn to an unspecified account. Cybersecurity experts cautioned that DarkSide's claim to have disbanded might be a ruse to deflect scrutiny, and possibly allow the gang to resume hacking activities under a different name. It is common for cybercriminal networks to shut down, revive, and rebrand in this way.
Agence France-Presse Agence France-Presse (; AFP) is a French international news agency headquartered in Paris, France. Founded in 1835 as Havas, it is the world's oldest news agency. With 2,400 employees of 100 nationalities, AFP has an editorial presence in 260 c ...
reporters discovered that the Recorded Future report which detailed the loss of DarkSide servers and funds was retweeted by the Twitter account of the 780th Military Intelligence Brigade, a US Army Cyberwarfare group involved in offensive operations.


Posterity

By April 2022, the
Federal Bureau of Investigation The Federal Bureau of Investigation (FBI) is the domestic Intelligence agency, intelligence and Security agency, security service of the United States and Federal law enforcement in the United States, its principal federal law enforcement ag ...
(FBI) released an advisory that several developers and money launderers for BlackCat had links to two defunct
ransomware as a service Ransomware as a service (RaaS) is a cybercrime business model where ransomware operators write software and affiliates pay to launch attacks using said software. Affiliates do not need to have technical skills of their own but rely on the technical ...
(RaaS) groups – DarkSide and BlackMatter. According to some experts, BlackCat might be a rebranding of DarkSide, after their attack of the Colonial Pipeline.


References

{{Hacking in the 2020s, state=autocollapse Hacker groups Hacking in the 2020s