darkside
1 incidentes
1 paises
0 sectores
ransomware RU Ultimo: 2026-06-25
DarkSide is a financially motivated cybercriminal group that first emerged in August 2020, rapidly evolving into a Ransomware-as-a-Service (RaaS) model by November 2020 and releasing version 2.0 of its ransomware in March 2021. The group is widely believed to operate from Eastern Europe, most likely Russia, and is assessed to be a for-profit operation rather than state-sponsored, though its activities against foreign targets are implicitly tolerated by Russian authorities. DarkSide's primary motivation is financial gain through a double extortion scheme, encrypting victim data and threatening to leak exfiltrated sensitive information if ransom demands are not met. What distinguishes DarkSide from many other groups is its professional and business-like operational structure, including offering technical support to victims who pay, conducting detailed financial research on targets, and publicly claiming to avoid non-profit sectors like healthcare and education, as well as organizations i
RansomLook pivots
Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.
Abrir perfil →
Paises objetivo (SOCRadar)
Argentina
Austria
AustraliaBosnia and Herzegovina
Belgium
Brazil
Canada
Chile
Germany
France
Sectores objetivo (SOCRadar)
Construction of BuildingsOther Information ServicesSoftware PublishersReal EstateTransportation Equipment ManufacturingAccommodationManufacturingConstructionPublic AdministrationAdministrative &Waste Management
URLs nuevas detectadas en IntelTracker