Bookkeeping Service Providers

  • Accounting
  • Bookkeeping
  • US Taxation
  • Financial Planning
  • Accounting Software
  • Small Business Finance
You are here: Home / SECURITY / Inside DarkSide: Researchers share intel on break-out cyber gang

Inside DarkSide: Researchers share intel on break-out cyber gang

May 12, 2021 by cbn Leave a Comment

In the wake of the Colonial Pipeline ransomware attack – which continues to disrupt supplies of fuel across the eastern and southern US – threat researchers from across the cyber community have been swapping information on the DarkSide ransomware gang, the up-and-coming cyber criminal group that has suddenly found itself elevated to global infamy.

First bursting onto the scene in August 2020 when it gained a certain measure of note by donating some of its ransom profits to charities, DarkSide is a (likely Russia-based) media-savvy group that understands how the cyber security “game” is played, and makes a virtue out of having an “honourable” reputation, as far as such a thing is possible in the cyber criminal underworld.

Clearly, say researchers, its operators like to see themselves as swashbuckling highwaymen, Robin Hood types who rob from the rich and give to the poor, although of course this is self-aggrandising nonsense, and borderline delusional narcissism.

But interestingly, in a departure from the more usual attention-seeking behaviour exhibited by other ransomware syndicates, the DarkSide group has been trying to distance itself from the attack, conducting an apparent damage limitation PR exercise, releasing a statement in broken English to the effect that its goal is “to make money, and not creating problems for society”. It is unclear from this line precisely what they thought they were doing up to now.

DarkSide also claimed that the attack on Colonial Pipeline was by an affiliate, and that it would police its partners’ selection of targets more assiduously in future to “avoid social consequences”. Again, it is unclear precisely what the group thought the consequences of its other attacks actually were.

Sophos’ Sean Gallagher, Mark Loman and Peter Mackenzie – who have dealt with several DarkSide victims via the firm’s incident response service – said this backpedalling was probably the result of the potentially greater real-world impact of their affiliate’s attack on the Colonial Pipeline.

“It has apparently made DarkSide’s operators more notorious than they are comfortable with,” they said in a newly published report.

“The gang previously promised to spare healthcare organisations, as well as others involved in vaccine distribution, because of the negative attention such attacks could potentially bring from within the gang’s home country. But because of the way DarkSide operates, it’s not clear how much control the keepers of the DarkSide brand have over the affiliates who do the actual work of breaking into networks and launching their ransomware.”

FireEye Mandiant’s researchers, Jordan Nuce, Jeremy Kennelly, Kimberly Goody, Andrew Moore, Alyssa Rahman, Brendan McKeague and Jared Wilson added: “A recent update to their underground forum advertisement also indicates that actors may attempt to DDoS [distributed denial of service] victim organisations.

“The actor ‘darksupp’ has stated that affiliates are prohibited from targeting hospitals, schools, universities, non-profit organisations and public sector entities.

“This may be an effort by the actor(s) to deter law enforcement action, since targeting of these sectors may invite additional scrutiny. Affiliates are also prohibited from targeting organisations in Commonwealth of Independent States (CIS) nations.”

Despite its sudden reticence, DarkSide has up to now followed in the footsteps of the other famous double extortion ransomware gangs, such as REvil/Sodinokibi, Maze and LockBit, exfiltrating data and threatening to release it if the victim does not pay. This is done via a Tor accessible blog. It is, however, known for making fairly hefty demands – one Sophos engagement was with a victim who was being extorted for $4m (they did not pay).

FireEye Mandiant’s team added that the gang’s affiliates receive a 25% cut of the ransom fees for hits that result in payments of under $500,000, and decrease to 10% for payments of over $5m.

Multifaceted extortion operation

The Mandiant team said it was clear that the DarkSide gang was becoming very proficient at “multifaceted extortion operations”. It noted the recent release of information suggesting that DarkSide would target NASDAQ and other listed companies by leaking their attacks to friendly traders in advance so they could short the victims and profit from any impact on the stock price.

“In another notable example,” they said, “an attacker was able to obtain the victim’s cyber insurance policy and leveraged this information during the ransom negotiation process, refusing to lower the ransom amount given their knowledge of the policy limits.

“This reinforces that during the post-exploitation phase of ransomware incidents, threat actors can engage in internal reconnaissance and obtain data to increase their negotiating power. We expect that the extortion tactics that threat actors use to pressure victims will continue to evolve throughout 2021.”

Tactics, techniques and procedures

They may be innovators in some regards, but for defenders concerned with stopping a DarkSide attack before it happens, researchers seem to agree that the DarkSide gang’s technological tactics, techniques and procedures (TTPs) also reflect other ransomwares, incorporating a mix of native Windows features, commodity malware and off-the-shelf red team tools such as Cobalt Strike.

The gang outsources compromise and deployment to network penetration specialists, who then refer the customer service operation back to the core operators. Sophos’ team believes these affiliates are likely hired guns who provide the same service to DarkSide’s peers. FireEye Mandiant confirmed this, saying it believes affiliates have also been associated with Babuk and REvil.

“In Sophos’ experience in data forensics and incident response to DarkSide attacks, the initial access to the target’s network came primarily as a result of phished credentials,” said the Sophos team. “This is not the only way ransomware attackers can gain a foothold, but it seems to be prevalent in cases involving this type of ransomware, possibly as a result of the affiliates’ preferences.”

Mandiant said it had also seen exploitation of CVE-2021-20016, a SQL injection vulnerability in the SonicWall SSLVPN SMA100 product that lets an unauthenticated attacker perform SQL queries to access usernames, passwords and other session-related information (if you are a SonicWall user, you should have patched this by now).

Mandiant tracks DarkSide activity in three different clusters of different groups – it defines these as UNC2628, UNC2659 and UNC2465 – that use differing methods of establishing persistence. Among other tools, UNC2628 favours the Cobalt Strike framework and BEACON payloads, sometimes uses Mimikatz for credential theft and exfiltration, and has even deployed F-Secure’s custom command and control framework. Meanwhile, UNC2659 uses TeamViewer to establish persistence, and UNC2465, the oldest cluster of activity linked to DarkSide, delivers the PowerShell-based .NET backdoor known as SMOKEDHAM.

Once established, Sophos’ intelligence has the gang’s dwell time at a median of 45 days, but it has been known to kick back for up to 88 days, during which time it steals as much data as possible, often targeting multiple departments inside the victim organisation – accounting and research and development (R&D) are particularly favoured here.

The gang moves around inside the victim network using PSExec and remote desktop connections – SSH if on a Linux server – and uploads its treasure trove to the cloud storage providers Mega or pCloud. Victims are extorted in bitcoin or monero – Sophos notes the gang does not accept Elon Musk’s favoured dogecoin.

“While some recent targeted ransomware operations from other gangs have sprung quickly, launching their attack within days, the actors behind DarkSide campaigns may spend weeks to months poking around inside an organisation’s network before activating their ransomware payload,” said the Sophos team.

Share on FacebookShare on TwitterShare on Google+Share on LinkedinShare on Pinterest

Filed Under: SECURITY

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Archives

  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • May 2021
  • April 2021
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • July 2019
  • June 2019
  • May 2019
  • April 2019
  • March 2019
  • February 2019
  • January 2019
  • December 2018
  • November 2018
  • October 2018
  • September 2018
  • August 2018
  • July 2018
  • June 2018
  • May 2018
  • April 2018
  • March 2018
  • February 2018
  • January 2018
  • December 2017
  • November 2017
  • October 2017
  • September 2017
  • August 2017
  • July 2017
  • May 2017
  • April 2017
  • March 2017
  • February 2017
  • January 2017
  • March 2016

Recent Posts

  • How Azure Cobalt 100 VMs are powering real-world solutions, delivering performance and efficiency results
  • FabCon Vienna: Build data-rich agents on an enterprise-ready foundation
  • Agent Factory: Connecting agents, apps, and data with new open standards like MCP and A2A
  • Azure mandatory multifactor authentication: Phase 2 starting in October 2025
  • Microsoft Cost Management updates—July & August 2025

Recent Comments

    Categories

    • Accounting
    • Accounting Software
    • BlockChain
    • Bookkeeping
    • CLOUD
    • Data Center
    • Financial Planning
    • IOT
    • Machine Learning & AI
    • SECURITY
    • Uncategorized
    • US Taxation

    Categories

    • Accounting (145)
    • Accounting Software (27)
    • BlockChain (18)
    • Bookkeeping (205)
    • CLOUD (1,322)
    • Data Center (214)
    • Financial Planning (345)
    • IOT (260)
    • Machine Learning & AI (41)
    • SECURITY (620)
    • Uncategorized (1,284)
    • US Taxation (17)

    Subscribe Our Newsletter

     Subscribing I accept the privacy rules of this site

    Copyright © 2025 · News Pro Theme on Genesis Framework · WordPress · Log in