Dark Power

First seen
2023-01-01 00:00:00
Malware type
ransomware
Family
Malware family
Profile updated
2026-07-07 13:49:17

Targeted industries: education-and-nonprofits healthcare-and-pharmaceutical manufacturing technology-and-telecommunications

Targeted regions: country_code:us country_code:ca country_code:cn country_code:jp country_code:fr country_code:de

Context

Dark Power is a ransomware group first observed in January 2023, known for targeting small to mid-sized organizations across education, healthcare, manufacturing, and information technology sectors. The group uses a double-extortion model, encrypting files and threatening to leak exfiltrated data via a Tor-based site if ransom demands are not met. Written in the Nim programming language, Dark Power ransomware appends the .dark_power extension to encrypted files and drops a ransom note named README.txt, giving victims 72 hours to contact them. The note typically demands payment in cryptocurrency and offers to negotiate. Victims have been observed in North America, Asia, and Europe, with attacks often involving exploitation of vulnerable public-facing systems or stolen credentials.

Reports & references

  • ransomlook.io — Dark Power (report)
  • trellix.com — Dark Power Ransomware (report)
  • bleepingcomputer.com — Dark Power Nim Based Ransomware Demands 10K From Victims (report)

External references