Overview
Platforms:
—
Variants:
—
Extensions:
—
ATT&CK software:
—
Initial access:
Phishing · Exploit Public-Facing Application · External Remote Services
Top countries:
—
Observed sectors:
—
Attribution
FIN7 / ELBRUS
VERIFIED
Operator attribution
Microsoft attributes the development and operation of the DarkSide ransomware-as-a-service ecosystem to the activity group it tracked as ELBRUS; MITRE associates DarkSide with FIN7.
Affiliates
DEV-0289
Documented DarkSide affiliate
Activity
Recent Observations
DarkSide affiliate program closes
May 2021
Operational closure
DarkSide announced the closure of its affiliate program following increased U.S. pressure and the loss of access to parts of its public infrastructure.
Colonial Pipeline attack
May 2021
Major incident
DarkSide ransomware was deployed against Colonial Pipeline, resulting in a precautionary shutdown of pipeline operations.
TTPs
ATT&CK coverage:
6 techniques
· 4 tactics
T1566
Phishing
VERIFIEDInitial Access
DarkSide actors were observed using phishing as an initial access method.
T1190
Exploit Public-Facing Application
VERIFIEDInitial Access
DarkSide actors were observed exploiting remotely accessible systems for initial access.
T1133
External Remote Services
VERIFIEDInitial Access
DarkSide actors used remotely accessible accounts, systems and virtual desktop infrastructure.
Show more TTPs (3)
T1021.001
Remote Desktop Protocol
VERIFIEDLateral Movement / Persistence
DarkSide actors were observed using Remote Desktop Protocol during intrusions.
T1090.003
Multi-hop Proxy
VERIFIEDCommand and Control
DarkSide actors primarily used Tor infrastructure for command-and-control communications.
T1486
Data Encrypted for Impact
VERIFIEDImpact
DarkSide ransomware encrypted victim data after network compromise.
Victims
Colonial Pipeline
CONFIRMED
Energy & Utilities organization in United States.
CVEs
No CVE associations available.
Infrastructure
DarkSide leak site
Tor-hosted infrastructure used to publish stolen victim information as part of DarkSide's double-extortion model.
Payment infrastructure
DarkSide operated payment infrastructure used for ransom negotiations and cryptocurrency transactions.
Timeline
2021-06
Colonial Pipeline ransom recovered
The U.S. Department of Justice announced the seizure of 63.7 bitcoin traceable to Colonial Pipeline's ransom payment.
2021-05
Colonial Pipeline attack
DarkSide ransomware was deployed against Colonial Pipeline, triggering the shutdown of pipeline operations as a precaution.
2021-05
DarkSide shuts down
The operation closed its affiliate program after losing access to public infrastructure and facing increased law-enforcement pressure.
Show more events (1)
2020-08
DarkSide operation emerges
DarkSide began operating as a ransomware-as-a-service ecosystem targeting large organizations.