darkbit logo

darkbit

1 incidentes 1 paises 1 sectores ransomware RU Ultimo: 2026-06-25
Ver en IntelTracker → APTTrail →
DarkBit is a politically-motivated ransomware group that first emerged in early 2023, notably around February 11, with its initial observed activity targeting an Israeli technical university. While some reports attribute the group to a Russian-speaking cybercrime gang, Israeli cybersecurity officials have linked DarkBit to Iranian government-sponsored threat actors like MuddyWater, an attribution supported by the strong anti-Israel sentiments expressed in their ransom notes and social media campaigns. The group's primary motivation combines political hacktivism, branding themselves as "Hackers for Good" against racism, fascism, and apartheid, with the financial gain typical of ransomware operations. DarkBit distinguishes itself through its explicit ideological messaging, its use of social media platforms for influence operations and data leaks, and its development of a custom Golang-based ransomware that is a modified variant of LockBit. The group operates using a Ransomware-as-a-Servi
Tecnicas MITRE
T1059.001, T1566.001, T1078, T1486, T1048

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

Iran (1)

Paises objetivo (SOCRadar)

ChinaIsraelIran, Islamic Republic ofUnited States

Sectores atacados

Government (1)

Sectores objetivo (SOCRadar)

Energy & Utilities ManufacturingInformation ServicesFinanceProfessional&Technical ServicesEnterprises & HoldingEducational ServicesHealthCare & Social AssistanceOtherPublic Administration

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com