Darkside

Inactive
Darkside ransomware group has started its operation in August of 2020 with the model of RaaS (Ransomware-as-a-Service). They have become known for their operations of large ransoms scale. They have announced that they prefer not to attack hospitals, schools, non-profits, and governments, but rather big organizations that can be able to pay large ransoms. Darkside ransomware group became very famous following the cyberattack of the Colonial Pipeline and Toshiba unit. The FBI finally terminate the Darkside operation and Managed to pull money from their wallets back.
10 Victims
Jul 31, 2020 First Discovered
May 12, 2021 Last Discovered
1953 Days Inactive
0% Infostealer
0/1 Sites Online
Known Locations (1)
darksidc3iux462n6yunevoag52ntvwp6wulaz3zirkmh4cnz6hhj7id.onion
Tools Used
CredentialTheft
Mimikatz, SessionGopher
DiscoveryEnum
ADRecon, AdFind, Advanced IP Scanner, SoftPerfect NetScan
Exfiltration
Bashupload, MEGA, RClone, Sendspace, pCloud
LOLBAS
PsExec
Networking
Plink
Offsec
Cobalt Strike, CrackMapExec, Impacket, PowerSploit
RMM-Tools
AnyDesk, GoToAssist, TightVNC
Intelligence
Victims (10)

Detailed victim list temporarily unavailable

This group has 10 victims. The victim list API is currently responding slowly for this dataset. Country, sector, and infostealer breakdowns are not available at this time. Basic stats (victim count, first/last seen) are shown above from a faster data source.