Description Summary
DarkSide was a ransomware-as-a-service that operated from August 2020 until May 2021. It is most infamous for the May 2021 attack on Colonial Pipeline, which disrupted fuel supplies across the U.S. East Coast and prompted a presidential emergency declaration. After the attack, the group's infrastructure went offline. Operators rebranded as BlackMatter and later ALPHV/BlackCat.
Threat Actor
Russian-speaking RaaS operators. The U.S. government recovered USD 2.3 million of the Colonial Pipeline ransom payment via a clawback operation.
Technical Indicators
Encryption Extension
.<8-character-victim-id>
Encryption Algorithm
Salsa20 (file content) + RSA-1024 (key wrapping)
Ransom Note Name
README.<id>.TXT
Targeted Industries
Energy, Manufacturing, Financial, Legal
First Seen
August 2020
Last Seen
May 2021 (infrastructure shutdown post-Colonial Pipeline)
Geographical Location
United States, Europe
MITRE ATT&CK Matrix
| Tactic | TTP | Technique Name |
|---|---|---|
| Initial Access x 3 | T1566 | Phishing |
| T1190 | Exploit Public-Facing Application | |
| T1078 | Valid Accounts | |
| Execution x 1 | T1059 | Command and Scripting Interpreter |
| Execution Persistence x 1 | T1053 | Scheduled Task/Job |
| Defense Evasion x 2 | T1562.001 | Disable or Modify Tools |
| T1070.004 | File Deletion | |
| Discovery x 2 | T1083 | File and Directory Discovery |
| T1082 | System Information Discovery | |
| Lateral Movement x 2 | T1021.001 | Remote Services: RDP |
| T1021.002 | SMB/Windows Admin Shares | |
| Exfiltration x 2 | T1041 | Exfiltration Over C2 Channel |
| T1567.002 | Exfiltration to Cloud Storage | |
| Impact x 3 | T1486 | Data Encrypted for Impact |
| T1490 | Inhibit System Recovery | |
| T1489 | Service Stop |