Overview

Platforms: —
Variants: —
Extensions: —
ATT&CK software: —
Initial access: Phishing · Exploit Public-Facing Application · External Remote Services
Top countries: —
Observed sectors: —

Attribution

FIN7 / ELBRUS VERIFIED
Operator attribution
Microsoft attributes the development and operation of the DarkSide ransomware-as-a-service ecosystem to the activity group it tracked as ELBRUS; MITRE associates DarkSide with FIN7.

Affiliates

DEV-0289
Documented DarkSide affiliate

Activity

Recent Observations

DarkSide affiliate program closes
May 2021
Operational closure
DarkSide announced the closure of its affiliate program following increased U.S. pressure and the loss of access to parts of its public infrastructure.
Colonial Pipeline attack
May 2021
Major incident
DarkSide ransomware was deployed against Colonial Pipeline, resulting in a precautionary shutdown of pipeline operations.

TTPs

ATT&CK coverage: 6 techniques · 4 tactics
T1566 Phishing
VERIFIED
Initial Access
DarkSide actors were observed using phishing as an initial access method.
T1190 Exploit Public-Facing Application
VERIFIED
Initial Access
DarkSide actors were observed exploiting remotely accessible systems for initial access.
T1133 External Remote Services
VERIFIED
Initial Access
DarkSide actors used remotely accessible accounts, systems and virtual desktop infrastructure.
Show more TTPs (3)
T1021.001 Remote Desktop Protocol
VERIFIED
Lateral Movement / Persistence
DarkSide actors were observed using Remote Desktop Protocol during intrusions.
T1090.003 Multi-hop Proxy
VERIFIED
Command and Control
DarkSide actors primarily used Tor infrastructure for command-and-control communications.
T1486 Data Encrypted for Impact
VERIFIED
Impact
DarkSide ransomware encrypted victim data after network compromise.

Victims

Colonial Pipeline CONFIRMED
May 2021 United States Energy & Utilities
Energy & Utilities organization in United States.

CVEs

No CVE associations available.

Infrastructure

DarkSide leak site
Tor-hosted infrastructure used to publish stolen victim information as part of DarkSide's double-extortion model.
Payment infrastructure
DarkSide operated payment infrastructure used for ransom negotiations and cryptocurrency transactions.

Timeline

2021-06
Colonial Pipeline ransom recovered
The U.S. Department of Justice announced the seizure of 63.7 bitcoin traceable to Colonial Pipeline's ransom payment.
2021-05
Colonial Pipeline attack
DarkSide ransomware was deployed against Colonial Pipeline, triggering the shutdown of pipeline operations as a precaution.
2021-05
DarkSide shuts down
The operation closed its affiliate program after losing access to public infrastructure and facing increased law-enforcement pressure.
Show more events (1)
2020-08
DarkSide operation emerges
DarkSide began operating as a ransomware-as-a-service ecosystem targeting large organizations.

Sources