Dark Project is a double extortion ransomware group targeting industrial and energy sectors since August 2026.
Analyst brief
Dark Project is a ransomware operation active since August 2026. The group primarily targets Manufacturing, Healthcare, Transportation, and Energy & Utilities sectors in the United States, United Kingdom, Philippines, Germany, Mexico, and Canada. Their key TTP involves a double extortion model, exfiltrating sensitive data before encrypting systems and threatening to leak it on their dark web portal. Defenders should focus on detecting data exfiltration, monitoring for network anomalies, and strengthening controls against common initial access vectors such as phishing and exposed RDP.
Dark Project
activecrime
Dark Project is a newly emerged ransomware leak operation active as of August 2026. The group utilizes a double extortion model (stealing sensitive data before encrypting local systems and threatening to leak it on their dark web portal).
What tactic does the Dark Project ransomware group use to pressure its victims?+
Dark Project uses a double extortion model, exfiltrating sensitive data before encrypting systems and threatening to leak it on their dark web portal.
What should defenders focus on to counter the common initial access vectors used by Dark Project?+
Defenders should focus on detecting data exfiltration, monitoring for network anomalies, and strengthening controls against common initial access vectors such as phishing and exposed RDP.