darkside logo

darkside

1 incidentes 1 paises 0 sectores ransomware RU Ultimo: 2026-06-25
Ver en IntelTracker → APTTrail →
DarkSide is a financially motivated cybercriminal group that first emerged in August 2020, rapidly evolving into a Ransomware-as-a-Service (RaaS) model by November 2020 and releasing version 2.0 of its ransomware in March 2021. The group is widely believed to operate from Eastern Europe, most likely Russia, and is assessed to be a for-profit operation rather than state-sponsored, though its activities against foreign targets are implicitly tolerated by Russian authorities. DarkSide's primary motivation is financial gain through a double extortion scheme, encrypting victim data and threatening to leak exfiltrated sensitive information if ransom demands are not met. What distinguishes DarkSide from many other groups is its professional and business-like operational structure, including offering technical support to victims who pay, conducting detailed financial research on targets, and publicly claiming to avoid non-profit sectors like healthcare and education, as well as organizations i
Tecnicas MITRE
T1498, T1547, T1055, T1566, T1574, T1078.001
CVEs relacionadas
CVE-2023-38831

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United States (1)

Paises objetivo (SOCRadar)

ArgentinaAustriaAustraliaBosnia and HerzegovinaBelgiumBrazilCanadaChileGermanyFrance

Sectores objetivo (SOCRadar)

Construction of BuildingsOther Information ServicesSoftware PublishersReal EstateTransportation Equipment ManufacturingAccommodationManufacturingConstructionPublic AdministrationAdministrative &Waste Management

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com