DarkSide Ransomware

Description Summary

DarkSide was a ransomware-as-a-service that operated from August 2020 until May 2021. It is most infamous for the May 2021 attack on Colonial Pipeline, which disrupted fuel supplies across the U.S. East Coast and prompted a presidential emergency declaration. After the attack, the group's infrastructure went offline. Operators rebranded as BlackMatter and later ALPHV/BlackCat.

Threat Actor

Russian-speaking RaaS operators. The U.S. government recovered USD 2.3 million of the Colonial Pipeline ransom payment via a clawback operation.

Technical Indicators

Encryption Extension
.<8-character-victim-id>
Encryption Algorithm
Salsa20 (file content) + RSA-1024 (key wrapping)
Ransom Note Name
README.<id>.TXT
Targeted Industries
Energy, Manufacturing, Financial, Legal
First Seen
August 2020
Last Seen
May 2021 (infrastructure shutdown post-Colonial Pipeline)
Geographical Location
United States, Europe

MITRE ATT&CK Matrix

Tactic TTP Technique Name
Initial Access x 3 T1566 Phishing
T1190 Exploit Public-Facing Application
T1078 Valid Accounts
Execution x 1 T1059 Command and Scripting Interpreter
Execution Persistence x 1 T1053 Scheduled Task/Job
Defense Evasion x 2 T1562.001 Disable or Modify Tools
T1070.004 File Deletion
Discovery x 2 T1083 File and Directory Discovery
T1082 System Information Discovery
Lateral Movement x 2 T1021.001 Remote Services: RDP
T1021.002 SMB/Windows Admin Shares
Exfiltration x 2 T1041 Exfiltration Over C2 Channel
T1567.002 Exfiltration to Cloud Storage
Impact x 3 T1486 Data Encrypted for Impact
T1490 Inhibit System Recovery
T1489 Service Stop