Darkside is a cybercriminal group operating a Ransomware-as-a-Service (RaaS) model targeting large organizations.
Analyst brief
Darkside is an organized cybercriminal group operating a Ransomware-as-a-Service (RaaS) model since August 2020. They primarily target large organizations capable of paying substantial ransoms, while stating they avoid hospitals, schools, non-profits, and governments. The group's key TTPs include custom ransomware deployment, data exfiltration, and double extortion tactics. Defenders should focus on detecting initial access vectors, particularly compromised remote access credentials, and monitoring for data exfiltration indicators that precede ransomware encryption.
darkside
crime
Darkside ransomware group has started its operation in August of 2020 with the model of RaaS (Ransomware-as-a-Service). They have become known for their operations of large ransoms scale. They have announced that they prefer not to attack hospitals, schools, non-profits, and governments, but rather big organizations that can be able to pay large ransoms. Darkside ransomware group became very famous following the cyberattack of the Colonial Pipeline and Toshiba unit. The FBI finally terminate the Darkside operation and Managed to pull money from their wallets back.