TLP:CLEAR
⚠ ECRIME · RUSSIA / EASTERN-EUROPE-BASED RAAS OPERATION · NO CONFIRMED STATE SPONSORSHIP
// Threat Actor Profile — Ransomware-as-a-Service (RaaS) Operation / Double-Extortion Ransomware

DARKSIDE

PROFILE COMPILED: 2026-09-12  |  SOURCES: CISA/FBI AA21-131A, U.S. DOJ, U.S. Treasury/OFAC, Mandiant/FireEye, CrowdStrike, Secureworks CTU, Flashpoint, Elliptic, Chainalysis, Emsisoft, Krebs on Security, Picus Security, ASEC, FortiGuard Labs, 15+ additional vendor/press sources
Status: BRAND DEFUNCT (SHUT DOWN 2021-05-13) — LINEAGE PERSISTS VIA SUCCESSOR RAAS
Threat Level: HIGH (Historical) / RESIDUAL VIA BLACKMATTER → BLACKCAT-ALPHV LINEAGE
Primary Motive: Financial Extortion — Double-Extortion Ransomware
Active Since: August 2020 (as branded RaaS)
MITRE ATT&CK: None assigned — no G-ID or S-ID for DarkSide as of 2026-09-12
$90M+
Ransom revenue tracked across 47 Bitcoin wallets in ~9 months (Elliptic)
80+
Named victims on the "Happy Blog" leak site across 15+ countries
85% / 15%
RaaS revenue split — affiliate share vs. core-operator share
3-GEN
Rebrand lineage: DarkSide → BlackMatter → BlackCat/ALPHV (disrupted Dec 2023)
00
Overview

DarkSide is a Russian-speaking ransomware-as-a-service (RaaS) operation that surfaced in August 2020 and, in nine months of activity, extracted more than $90 million in ransom payments from over 80 named victims before detonating the highest-profile ransomware incident in U.S. history — the May 2021 attack on Colonial Pipeline (Elliptic, "DarkSide Ransomware has Netted Over $90 million in Bitcoin"). DarkSide is not remembered for technical sophistication; its encryption scheme (Salsa20 + RSA-1024) and much of its intrusion toolkit were unremarkable by 2021 standards. It is remembered because it perfected the RaaS business model to the point of near-corporate professionalism — a support portal, a decryption-testing feature, revenue-based ransom calibration, and a public code of conduct excluding hospitals and schools — and then, almost by accident, hit a target whose collapse the U.S. government could not ignore.

DarkSide matters now less as an active threat (the brand shut itself down on May 13, 2021, six days after the Colonial Pipeline attack, under evident law-enforcement pressure) than as the origin point of a lineage that has proven remarkably durable. DarkSide's code and personnel are assessed to have migrated into BlackMatter (July–November 2021), and BlackMatter's operators and infrastructure are, in turn, documented to have reconstituted as BlackCat/ALPHV — the RaaS group the FBI disrupted in December 2023 after it had become one of the most prolific ransomware operations of its era. Individual affiliates who worked under the DarkSide banner, such as Mikhail Matveev ("Wazawaka"), have been separately documented cycling through Babuk, LockBit, and Hive as well — DarkSide is best understood not as a single closed organization but as one node in a fluid, overlapping Russian-speaking eCrime ecosystem whose personnel, tooling, and even source code persist across brand names and law-enforcement disruptions.

Where DarkSide sits in the current threat landscape, then, is as a case study and a cautionary template rather than a live adversary. It demonstrated — before Colonial Pipeline made it undeniable — that a purely profit-motivated criminal enterprise, entirely unconnected to state direction, can produce consequences (a declared U.S. federal emergency, a G7-level diplomatic response, mandatory new federal regulation of an entire critical-infrastructure sector) that rival those of nation-state operations. Every ransomware actor that has emerged since has operated in the regulatory and law-enforcement environment DarkSide's own collapse helped create.

01
Identity & Attribution
Primary NameDarkSide
Sponsor / ParentNone confirmed — independent financially motivated RaaS operation
Actor TypeRansomware-as-a-Service (RaaS) — core developer group + vetted criminal affiliate network
Primary MotivationFinancial — double-extortion ransomware
Active SinceAugust 2020 (branded RaaS launch); constituent affiliate infrastructure (UNC2465) traced to March/October 2020
Last ObservedDarkSide brand: May 13, 2021 (self-announced shutdown). Assessed lineage (BlackMatter → BlackCat/ALPHV) active through December 2023 FBI disruption.
MITRE G-IDNone assigned — DarkSide has no dedicated Group (G-ID) or Software (S-ID) entry in MITRE ATT&CK Enterprise as of 2026-09-12
Legal StatusNo core developer publicly indicted by name. DOJ seized 63.7 BTC (~$2.3M) of the Colonial ransom, Jun 2021. OFAC sanctioned SUEX OTC exchange, Sep 2021, for laundering proceeds from 8 ransomware variants incl. DarkSide. Affiliate Mikhail Matveev ("Wazawaka"/"Boriselcin") indicted by DOJ, May 2023, for ransomware activity spanning DarkSide, Babuk, LockBit, and Hive.
Tracking Aliases
DarkSide CARBON SPIDER (CrowdStrike — asserted operator of the DarkSide RaaS) GOLD WATERFALL (Secureworks — primary DarkSide-operator tracking name) GOLD NIAGARA / FIN7 / ITG14 / Sangria Tempest (suspected but explicitly unconfirmed link per Secureworks CTU) UNC2465 (Mandiant — tracked DarkSide affiliate cluster, supply-chain intrusion vector)
Attribution Confidence

[HIGH] that DarkSide's core operators and the great majority of its affiliates are Russian-speaking and operate from Russia or elsewhere in the former Soviet space — the ransomware payload itself refuses to execute on systems configured with Russian or other CIS-language locales, a self-protective measure consistent with operating from, and wishing to avoid prosecution within, that region (Flashpoint; CSO Online). [LOW] on any more specific organizational identity: vendors disagree. CrowdStrike attributes the DarkSide RaaS operation to CARBON SPIDER, the eCrime group more widely known as FIN7 — a financial-crime group active since at least 2013 that pivoted from point-of-sale malware to "big game hunting" ransomware. Secureworks, by contrast, tracks DarkSide's operators under a separate designation, GOLD WATERFALL, and states explicitly that it has "no direct observations that would confirm any link" to GOLD NIAGARA (its name for FIN7/Carbon Spider) — despite third-party researcher claims of overlap. Flashpoint separately assesses with moderate confidence that DarkSide's operators are former REvil affiliates. No single hypothesis is confirmed across independent vendors; this card treats DarkSide's organizational lineage as a genuinely open question rather than adopting any one vendor's attribution as fact.

02
Campaign & Operational Timeline
Aug 2020
RaaS Launch
DarkSide surfaces on Russian-language cybercrime forums, marketing itself with unusual professionalism: a stated (if selectively honored) exclusion policy against hospitals, schools, non-profits, and government targets, a decryptor-testing feature for negotiating victims, and a revenue-sharing affiliate model (Emsisoft, "Ransomware Profile: DarkSide"). Mandiant separately traces DarkSide-affiliate infrastructure (later designated UNC2465) to as early as March/October 2020.
Oct 2020 – Mar 2021
Scaling & V2.0 Release
DarkSide releases a v2.0 update (March 2021) with a Linux/ESXi-capable variant alongside the existing Windows payload, targeting virtualization infrastructure directly. Elliptic's later blockchain analysis identifies ransom flows to 47 distinct DarkSide-linked BTC wallets beginning in this window, ultimately totaling over $90 million, with the group's cut (~$15.5M) and affiliate share (~$74.7M) reflecting the RaaS revenue split.
Apr–May 2021
Brenntag & Colonial Pipeline Attacks
DarkSide affiliates hit Brenntag, a large German chemical distribution company, and — via a compromised legacy VPN account exploited April 29, 2021 — Colonial Pipeline Company, the largest U.S. refined-products pipeline operator. Elliptic notes roughly 10% of the group's entire nine-month revenue came from these two attacks in a single week. The Colonial Pipeline intrusion is documented separately in this repository's companion incident card (see Section 08).
May 13, 2021
Brand Shutdown
Six days after the Colonial Pipeline attack became public, DarkSide's operators announce they are shutting down the RaaS program, citing unspecified law-enforcement disruption of their leak-site, payment, and CDN infrastructure. Operators claim they will issue decryptors to affected affiliates' remaining victims and settle outstanding affiliate payments by May 23, 2021 (GovInfoSecurity; Intel 471).
May–Jun 2021
UNC2465 Software Supply-Chain Pivot
A DarkSide-affiliated cluster Mandiant tracks as UNC2465 compromises the website of a CCTV/surveillance vendor and trojanizes its Dahua SmartPSS Windows installer (available May 18 – June 8, 2021), delivering the custom SMOKEDHAM .NET backdoor to downstream victims who downloaded the legitimate-looking software — a rare documented instance of a ransomware-affiliated actor executing a genuine software supply-chain compromise (Mandiant/FireEye, "Smoking Out a DARKSIDE Affiliate's Supply Chain Software Compromise").
Jul 2021
BlackMatter Emerges
A new RaaS operation, BlackMatter, appears on cybercrime forums advertising itself explicitly as combining "the best features" of DarkSide, REvil, and LockBit. Independent code analysis of a leaked BlackMatter decryptor finds the RSA and Salsa20 cryptographic implementations are near-exact copies of DarkSide's, and CISA/NSA/FBI jointly assess BlackMatter as a likely DarkSide rebrand (CISA AA21-291A).
Oct–Nov 2021
BlackMatter Shutdown
Following a string of high-profile attacks on U.S. agricultural cooperatives and continued law-enforcement pressure, BlackMatter operators announce their own shutdown in November 2021, again promising decryption keys to remaining affiliate victims.
Nov 2021 – Dec 2023
BlackCat/ALPHV Lineage & FBI Disruption
BlackCat (ALPHV) emerges in November 2021; by April 2022 the FBI publicly assesses that several BlackCat developers and money launderers have direct links to the defunct DarkSide and BlackMatter operations, and BlackCat operators themselves have acknowledged the lineage. BlackCat/ALPHV goes on to become one of the most prolific ransomware operations of 2022–2023 before an FBI-led operation disrupts its leak-site and payment infrastructure in December 2023 (partially undone by the group in a subsequent apparent exit-scam against its own affiliates).
03
Attack Lifecycle Affiliate-driven intrusion chain under a shared RaaS toolkit

Entry vectors. Because DarkSide operated a RaaS model, initial access varied by affiliate rather than following one fixed playbook. Documented vectors include exploitation of exposed or compromised remote-access services (VPN and RDP) — the vector confirmed in the Colonial Pipeline intrusion, where a single legacy VPN account with a reused, leaked password and no MFA provided entry — as well as credentials purchased from third-party initial access brokers, targeted phishing, and, in the UNC2465 cluster's case, a genuine software supply-chain compromise: a trojanized installer for a legitimate CCTV management application, distributed from the vendor's own compromised website, that dropped the custom SMOKEDHAM backdoor onto downstream victims (Mandiant/FireEye).

Toolchain and internal operations. Once inside a network, DarkSide-affiliated intrusions consistently favor legitimate, dual-use tooling over bespoke malware — a deliberate choice to minimize antivirus and EDR detections. Advanced IP Scanner and BloodHound support internal reconnaissance and Active Directory attack-path mapping; Mimikatz harvests additional credentials; TeamViewer, downloaded from the vendor's official site, provides interactive persistence that blends with legitimate remote-access traffic. Where custom tooling appears, it tends to be narrowly purpose-built — SMOKEDHAM for initial-access credential capture and command execution, NGROK for outbound tunneling to attacker infrastructure — rather than a large bespoke framework. A documented DarkSide-specific capability distributes malicious Group Policy Objects across compromised Active Directory environments, pushing scheduled tasks to domain-joined hosts to self-propagate the ransomware payload without requiring the affiliate to manually stage each endpoint (ASEC).

C2, exfiltration, and impact. Command and control for the DarkSide-branded toolkit relies substantially on tunneling utilities like NGROK rather than dedicated bespoke C2 infrastructure — a further reflection of the "borrow legitimate tools" pattern. Data exfiltration ahead of encryption uses Rclone to move data in bulk to attacker-controlled cloud storage — the mechanism behind the roughly 100GB moved off Colonial Pipeline's network in a two-hour window — establishing the leverage for the group's double-extortion model before a single file is encrypted. Immediately before deploying the ransomware payload, DarkSide's toolkit executes a well-documented anti-recovery sequence: shadow-copy deletion via vssadmin or an equivalent PowerShell WMI call, disabling of Windows Recovery via bcdedit, and suspension of Windows Event Logging — then deploys the Salsa20/RSA-1024 payload itself, which performs a locale check and refuses to execute on Russian- or CIS-configured systems before encrypting files and dropping a ransom note directing the victim to a Tor-hosted negotiation and leak-site portal ("Happy Blog").

04
TTPs — MITRE ATT&CK Mapping Enterprise framework; confidence reflects strength and specificity of source documentation
Resource Development
T1588.002
Obtain Capabilities: Tool
[HIGH] Core RaaS operators develop and lease the ransomware payload, negotiation portal, and leak-site infrastructure to vetted affiliates for a revenue share (Emsisoft; CSO Online).
Initial Access
T1133
External Remote Services
[HIGH] Exploitation of exposed/compromised VPN and RDP services — confirmed vector in the Colonial Pipeline intrusion (a legacy, MFA-less VPN account).
Initial Access
T1195.002
Compromise Software Supply Chain
[HIGH] UNC2465 trojanized a legitimate CCTV vendor's Dahua SmartPSS installer to deliver SMOKEDHAM to downstream victims (Mandiant/FireEye) — an atypical but well-documented vector for this ecosystem.
Execution
T1059.001
PowerShell
[HIGH] PowerShell drives shadow-copy deletion (WMI Win32_Shadowcopy) and supports GPO-based scheduled-task deployment for self-propagation.
Persistence
T1053.005
Scheduled Task/Job
[MEDIUM] Malicious Group Policy Objects push scheduled tasks to domain-joined hosts to execute the ransomware payload AD-wide (ASEC).
Persistence
T1219
Remote Access Software
[MEDIUM] TeamViewer, downloaded from the vendor's official site, provides low-signature interactive persistence (Picus Security).
Credential Access
T1003
OS Credential Dumping
[MEDIUM] Mimikatz documented across DarkSide-affiliate campaigns generally for harvesting additional domain credentials.
Discovery
T1482
Domain Trust Discovery
[MEDIUM] BloodHound used for AD attack-path mapping ahead of lateral movement and privilege escalation.
Lateral Movement
T1021.001
Remote Desktop Protocol
[MEDIUM] RDP documented as a lateral-movement channel alongside abused legitimate remote-access tooling.
Command & Control
T1572
Protocol Tunneling
[MEDIUM] NGROK tunneling used by the UNC2465 cluster for outbound C2 alongside SMOKEDHAM (Mandiant/FireEye).
Defense Evasion
T1622
Debugger Evasion / Process Manipulation
[HIGH] Helper processes launched in CREATE_SUSPENDED state with garbage command-line arguments, with the true command line read from the process's PEB in memory after suspension — defeats command-line-based behavioral detection (FortiGuard Labs).
Defense Evasion / Discovery
T1614.001
System Location Discovery
[HIGH] Payload checks system locale/keyboard layout and refuses execution on Russian or CIS-language systems (Flashpoint; CSO Online).
Impact
T1490
Inhibit System Recovery
[HIGH] Documented commands: vssadmin delete shadows /all /quiet, PowerShell WMI shadow-copy deletion, and bcdedit /set {default} recoveryenabled No, executed immediately before encryption.
Impact
T1486
Data Encrypted for Impact
[HIGH] Hybrid Salsa20 (symmetric) + RSA-1024 (asymmetric) scheme; Windows and Linux/ESXi-capable variants existed by early-mid 2021 (Qualys; Akamai).
Impact
T1657
Financial Theft
[HIGH] Double-extortion model via the Tor-hosted "Happy Blog" leak site; over $90M tracked in ransom payments across 47 wallets (Elliptic).
05
Targeting Profile
Sector Targeting
Professional / Financial Services
PRIMARY
Manufacturing / Industrial
HIGH
Energy / Critical Infrastructure
HIGH
Legal Services
MED
Technology
MED
Retail
LOW
GeographiesMajority U.S.-based victims; documented Western European victims (Brenntag, Germany); explicit avoidance of Russia and other CIS states via locale-check evasion; 15+ countries represented on leak site overall
Victim ProfileMid-to-large enterprises assessed able to pay a substantial ransom; affiliates reportedly reviewed victim financials/insurance status to calibrate ransom demand size
Preferred EntryInternet-exposed or credential-compromised VPN/RDP; initial-access-broker-purchased footholds; opportunistic software supply-chain compromise (UNC2465)
Target DoctrinePublicly stated exclusion of hospitals, funeral services, schools/universities, non-profits, and government entities — explicitly to reduce law-enforcement and media attention; the policy did not prevent the Colonial Pipeline attack from triggering exactly that outcome
06
Tools, Malware & Infrastructure
DarkSide Ransomware RaaS Payload · Custom
Hybrid Salsa20 (symmetric, per-file key) + RSA-1024 (asymmetric, protects Salsa20 keys) encryption; Windows and Linux/ESXi-capable variants existed by the v2.0 release (March 2021). Performs a system-locale/keyboard-layout check at execution (T1614.001) and self-terminates on Russian/CIS-configured hosts. Preceded by a documented anti-recovery sequence (shadow-copy deletion, Windows Recovery disablement, Event Logging suspension). Helper processes are launched CREATE_SUSPENDED with garbage command-line arguments, with the real command line read post-launch from the process's PEB — a specific, documented EDR-evasion mechanism (T1622). Weaponized in the Colonial Pipeline attack (see companion incident card: output/incidents/2021-05-07_COLONIAL-PIPELINE.html).
SMOKEDHAM .NET Backdoor · Custom
Custom .NET backdoor active since at least 2019, distributed by the UNC2465 DarkSide-affiliate cluster via a trojanized CCTV-vendor software installer in May–June 2021. Supports keylogging, screenshot capture, and arbitrary command execution on infected hosts, providing the initial foothold and credential-capture capability for follow-on ransomware deployment (Mandiant/FireEye).
Mimikatz COTS / Dual-Use
Open-source Windows credential-dumping utility used to harvest cached credentials post-foothold to support lateral movement across compromised environments.
BloodHound COTS / Open Source
Active Directory attack-path mapping tool used to identify routes to domain-admin-equivalent access ahead of ransomware deployment.
Advanced IP Scanner COTS
Legitimately signed, free network-scanning utility used for internal host/network discovery; rarely flagged by antivirus, exploited for that reason.
TeamViewer (abused) LOLBin / Legitimate Software
Downloaded from the vendor's own site and repurposed for interactive persistence, blending with legitimate remote-access traffic patterns.
Rclone LOLBin / Open Source
Open-source cloud-storage sync utility used for bulk pre-encryption data exfiltration to attacker-controlled cloud storage, underpinning the double-extortion leverage.
NGROK Infrastructure / Legitimate Service
Legitimate tunneling service abused by the UNC2465 cluster for outbound command-and-control connectivity from compromised hosts (Mandiant/FireEye).
"Happy Blog" Leak Site Tor-Hosted Infrastructure
DarkSide's Tor-based name-and-shame extortion portal and negotiation channel, hosting stolen-data pages for named non-paying victims. Seized or taken offline around May 13, 2021, alongside the group's payment site and CDN.
07
Indicators of Compromise All IPs and domains defanged
⚠ IOC HANDLING — All IPs and domains in this table are defanged. Reconstruct before use in detection tooling. Reference URLs in Section 13 are NOT defanged.
Type Value / Description Source Date
NOTENo specific host, network, or file-hash IOC values are reproduced in this card. CISA/FBI published a dedicated Malware Analysis Report and a STIX/JSON indicator package specific to DarkSide (Joint Advisory AA21-131A, updated 2021-07-07 with the MAR); consult that primary source directly for reconstructable indicator values. This avoids transcribing indicators now more than five years past their operational relevance, which this repository's standing orders flag as of limited detection value regardless.
PROTOCOLOutbound tunneling via ngrok[.]io infrastructure observed for UNC2465-cluster C2 (specific ngrok subdomains not independently reproduced here)Mandiant/FireEye2021-05/06
LEAK SITEDarkSide "Happy Blog" — Tor (.onion) hidden service; specific onion address not independently reproduced here (rotated/seized May 2021)GovInfoSecurity; Intel 4712021-05
SUPPLY CHAINTrojanized Dahua SmartPSS Windows installer distributed from the legitimate vendor's compromised website (specific package hash not independently reproduced here)Mandiant/FireEye2021-05-18 to 2021-06-08
08
Analyst Assessment
Overall Threat LevelHIGH (Historical) — brand defunct, residual risk via lineage
Attribution Confidence[HIGH] region/language; [LOW] specific organizational identity — contested across vendors
TrajectoryBrand extinct since May 2021; personnel/code lineage demonstrated persistence through two further RaaS generations (BlackMatter, BlackCat/ALPHV) despite two additional law-enforcement disruptions
Most Dangerous CapabilityNot a technical capability — a professionalized, revenue-shared RaaS business model that scales extortion by separating tooling/negotiation infrastructure (core operators) from intrusion labor (affiliates), and that has proven durable enough to survive brand death three times over
Primary Intel GapNo confirmed identity for DarkSide's core developer(s); the FIN7/Carbon Spider vs. REvil-descended vs. wholly independent question remains open across vendors
Ecosystem / Affiliated Groups
BlackMatter (direct successor rebrand, Jul–Nov 2021) BlackCat / ALPHV (further lineage, disrupted Dec 2023 — see companion card) REvil (Flashpoint moderate-confidence shared-personnel hypothesis) FIN7 / Carbon Spider (CrowdStrike-asserted operator link, unconfirmed by Secureworks) UNC2465 (Mandiant-tracked affiliate cluster)

DarkSide's own technical capability was never the point; it was a merely competent implementation of hybrid symmetric/asymmetric encryption and double extortion that dozens of other 2020–2021-era ransomware families matched or exceeded. What made DarkSide analytically significant — and what this analyst assesses as its most dangerous and most durable capability — is organizational: a RaaS structure sophisticated enough to attract skilled affiliates (revenue-based ransom calibration, professional negotiation support, a public "code of conduct" designed to manage law-enforcement heat) while remaining resilient to the loss of its own brand. The DarkSide → BlackMatter → BlackCat/ALPHV lineage, corroborated by independent code analysis and an FBI advisory naming shared personnel, demonstrates that shutting down a RaaS brand does not remove its operators, its affiliates, or often its source code from the threat landscape — it typically just changes the name on the leak site for a period of months.

The central attribution question this card leaves open — whether DarkSide's core operators are the eCrime group CrowdStrike tracks as CARBON SPIDER (better known publicly as FIN7), a Flashpoint-assessed REvil offshoot, or an organizationally distinct entity — is not resolved by the available public evidence, and this analyst declines to adopt any single vendor's position as settled fact given that Secureworks, the vendor closest to the claimed FIN7 link, explicitly states it has no direct observations confirming that connection. What would change this assessment: an unsealed U.S. indictment naming a specific individual as a DarkSide core developer (as opposed to an affiliate, which the Matveev indictment already covers), or forensic malware-lineage analysis directly linking DarkSide's original codebase to a previously attributed FIN7/Carbon Spider or REvil toolset rather than to shared affiliate personnel alone.

Forward risk trajectory: DarkSide-as-brand poses no ongoing direct risk. The pattern it established — rapid shutdown under pressure followed by reconstitution under a new name with overlapping personnel — is now a well-documented feature of the broader RaaS ecosystem, observed again with BlackCat/ALPHV's own late-2023/2024 disruption and apparent affiliate exit-scam. Organizations should treat any newly emerging RaaS brand exhibiting DarkSide-lineage tradecraft signatures (Salsa20/RSA-1024-family cryptography, CIS locale-check evasion, GPO-based self-propagation, heavy reliance on TeamViewer/Rclone/BloodHound) as a plausible continuation of this lineage rather than an unrelated, unknown actor.

09
Defensive Recommendations
01
Enforce MFA on all remote-access services. VPN, RDP, and Citrix/remote-desktop gateways should require multi-factor authentication without exception, including legacy or infrequently used accounts.
Counters: T1133, T1078
02
Enforce remote-access account lifecycle management. Automatically disable VPN/remote-access accounts on role change or departure, and periodically audit for enabled-but-unused accounts.
Counters: T1133, T1078
03
Deploy dark-web credential-exposure monitoring. Screen corporate credentials against known breach/leak datasets to catch password reuse before an attacker does.
Counters: T1078
04
Audit and alert on Group Policy Object changes. Monitor for unauthorized GPO modifications, particularly those creating new scheduled tasks across domain-joined hosts.
Counters: T1053.005
05
Restrict legitimate remote-access tools via application allowlisting. Block or tightly control TeamViewer, AnyDesk, and similar tools where not explicitly business-required.
Counters: T1219
06
Monitor for bulk cloud-sync exfiltration tooling. Alert on Rclone execution or equivalent cloud-sync utility activity, and apply egress filtering/DLP against unauthorized cloud-storage destinations.
Counters: T1567.002
07
Protect and alert on Volume Shadow Copy Service activity. Alert on vssadmin delete shadows, equivalent PowerShell/WMI shadow-copy deletion, and bcdedit recovery-disabling commands.
Counters: T1490
08
Verify software supply-chain integrity. Validate installer signatures/hashes against vendor-published values before deployment, particularly for niche vendor software (e.g., surveillance/CCTV management tools) with less mature update-integrity practices.
Counters: T1195.002
10
OPSEC Procedures Observed infrastructure hygiene, rotation patterns, anti-forensics
Infrastructure Rotation [MEDIUM]
DarkSide's Tor-hosted leak site, payment portal, and CDN infrastructure were abandoned abruptly on May 13, 2021, days after Colonial Pipeline drew intense law-enforcement attention, rather than on any observable fixed rotation schedule — consistent with reactive, heat-driven infrastructure abandonment rather than proactive hygiene (GovInfoSecurity; Intel 471). No public reporting documents a routine pre-Colonial rotation cadence.
Living-off-the-Land Ratio [MEDIUM]
Documented intrusions rely heavily on legitimate, dual-use tooling — TeamViewer, Advanced IP Scanner, BloodHound, native PowerShell/WMI, and Windows Group Policy/scheduled-task mechanisms — with custom code largely confined to the ransomware payload itself and, in the UNC2465 cluster, the SMOKEDHAM backdoor. This heavy LOLBin/dual-use-tool preference is consistent with the broader affiliate-driven RaaS trend of minimizing bespoke-malware detection surface (Picus Security).
Anti-Forensics Routines [HIGH]
Immediately before encryption, the payload executes a documented anti-recovery/anti-forensics sequence: shadow-copy deletion (vssadmin delete shadows /all /quiet or the PowerShell WMI equivalent Get-WmiObject Win32_Shadowcopy|ForEach-Object {$_.Delete();}), disabling of Windows Recovery (bcdedit /set {default} recoveryenabled No), and suspension of Windows Event Logging to deny defenders a post-incident audit trail (community malware analysis; FortiGuard Labs).
Tooling Hygiene [HIGH]
A specific, well-documented anti-detection technique: helper processes are spawned in a CREATE_SUSPENDED state with deliberately garbled/garbage command-line arguments visible to process-creation telemetry (Sysmon Event ID 1, EDR process logs), and the malware then reads its true command line directly from the target process's PEB (Process Environment Block) in memory post-suspension, before resuming execution — specifically engineered to defeat command-line-string-based behavioral detection rules (FortiGuard Labs).
11
Detection Evasion Specific techniques, LOLBin sequences, EDR bypass patterns
Suspended-Process Command-Line Spoofing + PEB Read T1622 / T1027
EDR BYPASS
Helper binaries are launched with the Windows API in a CREATE_SUSPENDED state, presenting deliberately garbled/garbage arguments to any process-creation monitoring (Sysmon Event ID 1, EDR command-line telemetry) that inspects the process at launch. After suspension, the malware reads the true, intended command line directly from the target process's Process Environment Block (PEB) in memory, then resumes execution with the real arguments applied internally — meaning any detection rule keyed on the visibly logged command-line string never sees the actual invocation (FortiGuard Labs, "Stomping Shadow Copies — A Second Look Into Deletion Methods").
Specific garbage-argument patterns and exact API call sequence not publicly documented in detail as of 2026-09-12; the CREATE_SUSPENDED + PEB-read mechanism itself is independently corroborated across FortiGuard Labs and community malware-analysis reporting.
Volume Shadow Copy & Recovery Disablement T1490
EDR BYPASS SIEM EVASION
Immediately prior to encryption, the payload eliminates local recovery options to make the extortion demand the only realistic restoration path.
vssadmin delete shadows /all /quiet Get-WmiObject Win32_Shadowcopy | ForEach-Object {$_.Delete();} bcdedit /set {default} recoveryenabled No
Windows Event Logging Suspension T1562.002
SIEM EVASION
Documented as part of the pre-encryption anti-forensics sequence, denying defenders the audit trail needed to reconstruct the intrusion timeline after the fact.
Specific API calls, registry modifications, or service-manipulation commands used to suspend Event Logging are not publicly documented in detail as of 2026-09-12.
Locale / Geofencing Self-Termination T1614.001
NETWORK EDR BYPASS
The payload checks system locale and installed keyboard layout at execution and self-terminates without encrypting on hosts configured for Russian or other CIS languages — simultaneously an operational-security measure (avoiding prosecution risk in the operators' home region) and a practical evasion technique that reduces exposure to security-vendor sandboxes and honeypots commonly configured with those locale settings (Flashpoint; CSO Online).
Specific locale/language-ID value list checked by the binary not publicly documented in detail as of 2026-09-12.
Legitimate-Tool Blending for AV/EDR Suppression T1219 / T1105
EDR BYPASS
Validly signed, legitimate software (TeamViewer downloaded from the vendor's own site, Advanced IP Scanner) is deliberately preferred over custom tooling for persistence and reconnaissance specifically because these binaries rarely trigger antivirus or EDR alerts compared to bespoke or previously catalogued malware (Picus Security).
No further command-level specifics beyond standard vendor-documented tool usage are publicly available as of 2026-09-12.
12
Emulation Resources MITRE CTID & Published Adversary Emulation Plans
MITRE CTID — NOT AVAILABLE No Adversary Emulation Plan Published
The MITRE Center for Threat-Informed Defense's Adversary Emulation Library (ctid.mitre.org/resources/adversary-emulation-library) was searched directly for DarkSide and BlackMatter plans as of 2026-09-12. The library includes published plans for actors such as FIN6 and menuPass, but no plan exists for DarkSide, BlackMatter, or BlackCat/ALPHV. No MITRE CTID adversary emulation plan has been published for this actor or its successor lineage as of 2026-09-12.
Additional Emulation Resources
CISA
Vendor detection resource · Accessed: 2026-09-12
Atomic Red Team
No DarkSide-named test identified in the redcanaryco/atomic-red-team repository as of 2026-09-12. Generic technique-level tests exist for constituent techniques used by DarkSide — T1490 (Inhibit System Recovery) and T1003 (OS Credential Dumping) — but no scenario is scoped to DarkSide specifically.
Gap noted · Checked: 2026-09-12
SigmaHQ
No DarkSide-named rule identified in the SigmaHQ/sigma repository as of 2026-09-12. Generic ransomware-behavior and shadow-copy-deletion Sigma rules in the repository (e.g., rules/category/antivirus/av_ransomware.yml, network-scanner PUA rules covering Advanced IP Scanner) provide partial, technique-level coverage rather than actor-specific detections.
Gap noted · Checked: 2026-09-12
13
References URLs are NOT defanged — navigate directly
CISA / NSA / FBI
Accessed: 2026-09-12
CrowdStrike
Accessed: 2026-09-12
Secureworks CTU
Accessed: 2026-09-12
Malpedia
Accessed: 2026-09-12
Chainalysis
Accessed: 2026-09-12
Emsisoft
Accessed: 2026-09-12
Krebs on Security
Accessed: 2026-09-12
GovInfoSecurity
Accessed: 2026-09-12
Wikipedia
Accessed: 2026-09-12
Qualys
Accessed: 2026-09-12
MITRE CTID
Accessed: 2026-09-12