DarkSide is a Russian-speaking ransomware-as-a-service (RaaS) operation that surfaced in August 2020 and, in nine months of activity, extracted more than $90 million in ransom payments from over 80 named victims before detonating the highest-profile ransomware incident in U.S. history — the May 2021 attack on Colonial Pipeline (Elliptic, "DarkSide Ransomware has Netted Over $90 million in Bitcoin"). DarkSide is not remembered for technical sophistication; its encryption scheme (Salsa20 + RSA-1024) and much of its intrusion toolkit were unremarkable by 2021 standards. It is remembered because it perfected the RaaS business model to the point of near-corporate professionalism — a support portal, a decryption-testing feature, revenue-based ransom calibration, and a public code of conduct excluding hospitals and schools — and then, almost by accident, hit a target whose collapse the U.S. government could not ignore.
DarkSide matters now less as an active threat (the brand shut itself down on May 13, 2021, six days after the Colonial Pipeline attack, under evident law-enforcement pressure) than as the origin point of a lineage that has proven remarkably durable. DarkSide's code and personnel are assessed to have migrated into BlackMatter (July–November 2021), and BlackMatter's operators and infrastructure are, in turn, documented to have reconstituted as BlackCat/ALPHV — the RaaS group the FBI disrupted in December 2023 after it had become one of the most prolific ransomware operations of its era. Individual affiliates who worked under the DarkSide banner, such as Mikhail Matveev ("Wazawaka"), have been separately documented cycling through Babuk, LockBit, and Hive as well — DarkSide is best understood not as a single closed organization but as one node in a fluid, overlapping Russian-speaking eCrime ecosystem whose personnel, tooling, and even source code persist across brand names and law-enforcement disruptions.
Where DarkSide sits in the current threat landscape, then, is as a case study and a cautionary template rather than a live adversary. It demonstrated — before Colonial Pipeline made it undeniable — that a purely profit-motivated criminal enterprise, entirely unconnected to state direction, can produce consequences (a declared U.S. federal emergency, a G7-level diplomatic response, mandatory new federal regulation of an entire critical-infrastructure sector) that rival those of nation-state operations. Every ransomware actor that has emerged since has operated in the regulatory and law-enforcement environment DarkSide's own collapse helped create.
[HIGH] that DarkSide's core operators and the great majority of its affiliates are Russian-speaking and operate from Russia or elsewhere in the former Soviet space — the ransomware payload itself refuses to execute on systems configured with Russian or other CIS-language locales, a self-protective measure consistent with operating from, and wishing to avoid prosecution within, that region (Flashpoint; CSO Online). [LOW] on any more specific organizational identity: vendors disagree. CrowdStrike attributes the DarkSide RaaS operation to CARBON SPIDER, the eCrime group more widely known as FIN7 — a financial-crime group active since at least 2013 that pivoted from point-of-sale malware to "big game hunting" ransomware. Secureworks, by contrast, tracks DarkSide's operators under a separate designation, GOLD WATERFALL, and states explicitly that it has "no direct observations that would confirm any link" to GOLD NIAGARA (its name for FIN7/Carbon Spider) — despite third-party researcher claims of overlap. Flashpoint separately assesses with moderate confidence that DarkSide's operators are former REvil affiliates. No single hypothesis is confirmed across independent vendors; this card treats DarkSide's organizational lineage as a genuinely open question rather than adopting any one vendor's attribution as fact.
Entry vectors. Because DarkSide operated a RaaS model, initial access varied by affiliate rather than following one fixed playbook. Documented vectors include exploitation of exposed or compromised remote-access services (VPN and RDP) — the vector confirmed in the Colonial Pipeline intrusion, where a single legacy VPN account with a reused, leaked password and no MFA provided entry — as well as credentials purchased from third-party initial access brokers, targeted phishing, and, in the UNC2465 cluster's case, a genuine software supply-chain compromise: a trojanized installer for a legitimate CCTV management application, distributed from the vendor's own compromised website, that dropped the custom SMOKEDHAM backdoor onto downstream victims (Mandiant/FireEye).
Toolchain and internal operations. Once inside a network, DarkSide-affiliated intrusions consistently favor legitimate, dual-use tooling over bespoke malware — a deliberate choice to minimize antivirus and EDR detections. Advanced IP Scanner and BloodHound support internal reconnaissance and Active Directory attack-path mapping; Mimikatz harvests additional credentials; TeamViewer, downloaded from the vendor's official site, provides interactive persistence that blends with legitimate remote-access traffic. Where custom tooling appears, it tends to be narrowly purpose-built — SMOKEDHAM for initial-access credential capture and command execution, NGROK for outbound tunneling to attacker infrastructure — rather than a large bespoke framework. A documented DarkSide-specific capability distributes malicious Group Policy Objects across compromised Active Directory environments, pushing scheduled tasks to domain-joined hosts to self-propagate the ransomware payload without requiring the affiliate to manually stage each endpoint (ASEC).
C2, exfiltration, and impact. Command and control for the DarkSide-branded toolkit relies substantially on tunneling utilities like NGROK rather than dedicated bespoke C2 infrastructure — a further reflection of the "borrow legitimate tools" pattern. Data exfiltration ahead of encryption uses Rclone to move data in bulk to attacker-controlled cloud storage — the mechanism behind the roughly 100GB moved off Colonial Pipeline's network in a two-hour window — establishing the leverage for the group's double-extortion model before a single file is encrypted. Immediately before deploying the ransomware payload, DarkSide's toolkit executes a well-documented anti-recovery sequence: shadow-copy deletion via vssadmin or an equivalent PowerShell WMI call, disabling of Windows Recovery via bcdedit, and suspension of Windows Event Logging — then deploys the Salsa20/RSA-1024 payload itself, which performs a locale check and refuses to execute on Russian- or CIS-configured systems before encrypting files and dropping a ransom note directing the victim to a Tor-hosted negotiation and leak-site portal ("Happy Blog").
vssadmin delete shadows /all /quiet, PowerShell WMI shadow-copy deletion, and bcdedit /set {default} recoveryenabled No, executed immediately before encryption.output/incidents/2021-05-07_COLONIAL-PIPELINE.html).| Type | Value / Description | Source | Date |
|---|---|---|---|
| NOTE | No specific host, network, or file-hash IOC values are reproduced in this card. CISA/FBI published a dedicated Malware Analysis Report and a STIX/JSON indicator package specific to DarkSide (Joint Advisory AA21-131A, updated 2021-07-07 with the MAR); consult that primary source directly for reconstructable indicator values. This avoids transcribing indicators now more than five years past their operational relevance, which this repository's standing orders flag as of limited detection value regardless. | ||
| PROTOCOL | Outbound tunneling via ngrok[.]io infrastructure observed for UNC2465-cluster C2 (specific ngrok subdomains not independently reproduced here) | Mandiant/FireEye | 2021-05/06 |
| LEAK SITE | DarkSide "Happy Blog" — Tor (.onion) hidden service; specific onion address not independently reproduced here (rotated/seized May 2021) | GovInfoSecurity; Intel 471 | 2021-05 |
| SUPPLY CHAIN | Trojanized Dahua SmartPSS Windows installer distributed from the legitimate vendor's compromised website (specific package hash not independently reproduced here) | Mandiant/FireEye | 2021-05-18 to 2021-06-08 |
DarkSide's own technical capability was never the point; it was a merely competent implementation of hybrid symmetric/asymmetric encryption and double extortion that dozens of other 2020–2021-era ransomware families matched or exceeded. What made DarkSide analytically significant — and what this analyst assesses as its most dangerous and most durable capability — is organizational: a RaaS structure sophisticated enough to attract skilled affiliates (revenue-based ransom calibration, professional negotiation support, a public "code of conduct" designed to manage law-enforcement heat) while remaining resilient to the loss of its own brand. The DarkSide → BlackMatter → BlackCat/ALPHV lineage, corroborated by independent code analysis and an FBI advisory naming shared personnel, demonstrates that shutting down a RaaS brand does not remove its operators, its affiliates, or often its source code from the threat landscape — it typically just changes the name on the leak site for a period of months.
The central attribution question this card leaves open — whether DarkSide's core operators are the eCrime group CrowdStrike tracks as CARBON SPIDER (better known publicly as FIN7), a Flashpoint-assessed REvil offshoot, or an organizationally distinct entity — is not resolved by the available public evidence, and this analyst declines to adopt any single vendor's position as settled fact given that Secureworks, the vendor closest to the claimed FIN7 link, explicitly states it has no direct observations confirming that connection. What would change this assessment: an unsealed U.S. indictment naming a specific individual as a DarkSide core developer (as opposed to an affiliate, which the Matveev indictment already covers), or forensic malware-lineage analysis directly linking DarkSide's original codebase to a previously attributed FIN7/Carbon Spider or REvil toolset rather than to shared affiliate personnel alone.
Forward risk trajectory: DarkSide-as-brand poses no ongoing direct risk. The pattern it established — rapid shutdown under pressure followed by reconstitution under a new name with overlapping personnel — is now a well-documented feature of the broader RaaS ecosystem, observed again with BlackCat/ALPHV's own late-2023/2024 disruption and apparent affiliate exit-scam. Organizations should treat any newly emerging RaaS brand exhibiting DarkSide-lineage tradecraft signatures (Salsa20/RSA-1024-family cryptography, CIS locale-check evasion, GPO-based self-propagation, heavy reliance on TeamViewer/Rclone/BloodHound) as a plausible continuation of this lineage rather than an unrelated, unknown actor.
vssadmin delete shadows, equivalent PowerShell/WMI shadow-copy deletion, and bcdedit recovery-disabling commands.vssadmin delete shadows /all /quiet or the PowerShell WMI equivalent Get-WmiObject Win32_Shadowcopy|ForEach-Object {$_.Delete();}), disabling of Windows Recovery (bcdedit /set {default} recoveryenabled No), and suspension of Windows Event Logging to deny defenders a post-incident audit trail (community malware analysis; FortiGuard Labs).rules/category/antivirus/av_ransomware.yml, network-scanner PUA rules covering Advanced IP Scanner) provide partial, technique-level coverage rather than actor-specific detections.