DarkBit
- First seen
- 2023-05-01 00:00:00
- Malware type
- ransomware
- Profile updated
- 2026-07-07 12:52:21
Targeted industries: education-and-nonprofits government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:ir country_code:il
Context
DarkBit is a ransomware variant discovered in 2023, known for targeting the education sector and public sector organizations in Iran and Israel. It demands ransom payments and typically causes significant operational disruption.
Detection coverage
- 3 YARA rules
Detection rules
- SIGNATURE_BASE_MAL_RANSOM_Darkbit_Feb23_1 (yara-rule)
- SIGNATURE_BASE_MAL_RANSOM_Darkbit_Feb23_2 (yara-rule)
- MALPEDIA_Win_Darkbit_Auto (yara-rule)
Reports & references
- Microsoft — Mercury And Dev 1084 Destructive Attack On Hybrid Environment (report)
- blogs.blackberry.com — Darkbit Ransomware Targets Israel (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Darkbit (report)
- github.com — Readme.Md (report)
- labs.k7computing.com — Muddywater Back With Darkbit (report)
- twitter.com — 1626535098039271425 (report)