Darkside
Aliases: BlackMatter
- First seen
- 2020-08-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Last IoC activity
- 2026-07-19 17:16:14
- Profile updated
- 2026-07-07 12:58:09
Targeted industries: energy-and-utilities financial-services manufacturing technology-and-telecommunications
Context
Darkside, the latest ransomware operation to emerge has been attacking organizations beginning earlier this month. Darkside’s customized attacks on companies have already garnered them million-dollar payouts. Through their “press release”, these threat actors have claimed to be affiliated with prior ransomware operations making millions of dollars. They stated that they created this new product to match their needs, as prior products didn’t. Darkside explains that they only target companies they know that can pay the specified ransom. They have allegedly promised that they will not attack the following sectors. They include medicine, education, non-profit organizations, and the government sector.
Detection coverage
- 12 YARA rules
Detection rules
- TRELLIX_ARC_RANSOM_Darkside (yara-rule)
- TRELLIX_ARC_RANSOM_Darkside_DLL_May2021 (yara-rule)
- ARKBIRD_SOLG_RAN_ELF_Darkside_Apr_2021_1 (yara-rule)
- DITEKSHEN_MALWARE_Win_Blackmatter (yara-rule)
- DITEKSHEN_MALWARE_Win_Exmatter (yara-rule)
- DITEKSHEN_INDICATOR_KB_ID_Ransomware_Darkside (yara-rule)
- SEKOIA_Ransomware_Win_Blackmatter (yara-rule)
- SIGNATURE_BASE_MAL_RANSOM_Darkside_May21_1 (yara-rule)
- SIGNATURE_BASE_MAL_Ransomware_Win_DARKSIDE_V1_1 (yara-rule)
- SIGNATURE_BASE_MAL_Dropper_Win_Darkside_1 (yara-rule)
- MALPEDIA_Win_Blackmatter_Auto (yara-rule)
- MALPEDIA_Win_Darkside_Auto (yara-rule)
Reports & references
- CrowdStrike — Report2021Gtr (report)
- CrowdStrike — Carbon Spider Sprite Spider Target Esxi Servers With Ransomware (report)
- youtube.com — Watch (report)
- secureworks.com — Gold Waterfall (report)
- secureworks.com — Ransomware Groups Use Tor Based Backdoor For Persistent Access (report)
- Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
- CrowdStrike — Carbon Spider Embraces Big Game Hunting Part 1 (report)
- blogs.vmware.com — Esxi Targeting Ransomware The Threats That Are After Your Virtual Machines Part 1 (report)
- CrowdStrike — Big Game Hunting On The Rise Again According To Ecrime Index (report)
- CrowdStrike — How Big Game Hunting Ttps Shifted After Darkside Pipeline Attack (report)
- vmware.com — Vmw Exposing Malware In Linux Based Multi Cloud Environments (report)
- blogs.blackberry.com — Kraken The Code On Prometheus (report)
- docs.google.com — 1Mi8Z2Tbhmqq5X8Wf Ozv3Dvjz5Sjos 3 (report)
- ke-la.com — How Ransomware Gangs Find New Monetization Schemes And Evolve In Marketing (report)
- krebsonsecurity.com — Ransomware Gangs And The Name Game Distraction (report)
- news.sophos.com — The Ransomware Threat Intelligence Center (report)
- Broadcom/Symantec — The Ransomware Threat September 2021 (report)
- therecord.media — An Interview With Blackmatter A New Ransomware Group Thats Learning From The Mistakes Of Darkside And Revil (report)
- therecord.media — Darkside Gang Estimated To Have Made Over 90 Million From Ransomware Attacks (report)
- therecord.media — Darkside Ransomware Gang Says It Lost Control Of Its Servers Money A Day After Biden Threat (report)
- vulnerability.ch — Ransomware And Date Leak Site Publication Time Analysis (report)
- accenture.com — Evolving Danger Ransomware Extortion (report)
- bleepingcomputer.com — Blackmatter Ransomware Gang Rises From The Ashes Of Darkside Revil (report)
- bleepingcomputer.com — Darkside Ransomware Made 90 Million In Just Nine Months (report)
- bleepingcomputer.com — Popular Russian Hacking Forum Xss Bans All Ransomware Topics (report)