DarkBit

First seen
2023-05-01 00:00:00
Malware type
ransomware
Profile updated
2026-07-07 12:52:21

Targeted industries: education-and-nonprofits government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:ir country_code:il

Context

DarkBit is a ransomware variant discovered in 2023, known for targeting the education sector and public sector organizations in Iran and Israel. It demands ransom payments and typically causes significant operational disruption.

Detection coverage

  • 3 YARA rules

Detection rules

  • SIGNATURE_BASE_MAL_RANSOM_Darkbit_Feb23_1 (yara-rule)
  • SIGNATURE_BASE_MAL_RANSOM_Darkbit_Feb23_2 (yara-rule)
  • MALPEDIA_Win_Darkbit_Auto (yara-rule)

Reports & references

  • Microsoft — Mercury And Dev 1084 Destructive Attack On Hybrid Environment (report)
  • blogs.blackberry.com — Darkbit Ransomware Targets Israel (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Darkbit (report)
  • github.com — Readme.Md (report)
  • labs.k7computing.com — Muddywater Back With Darkbit (report)
  • twitter.com — 1626535098039271425 (report)

External references