Actor-claimed victim evidence. This listing is not independent confirmation of compromise.
Actor Claimeddarkside
Darkside ransomware group has started its operation in August of 2020 with the model of RaaS (Ransomware-as-a-Service). They have become known for their operations of large ransoms scale. They have announced that they prefer not to attack hospitals, schools, non-profits, and governments, but rather big organizations that can be able to pay large ransoms. Darkside ransomware group became very famous following the cyberattack of the Colonial Pipeline and Toshiba unit. The FBI finally terminate the Darkside operation and Managed to pull money from their wallets back.
Activity timeline
A dated ledger of actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Each date states what it measures. For extensive leak-site histories, victim entries are limited to the 100 most recent distinct listings.
Types: onion.
Actor-claimed victim evidence. This listing is not independent confirmation of compromise.
Actor ClaimedActor-claimed victim evidence. This listing is not independent confirmation of compromise.
Actor ClaimedActor-claimed victim evidence. This listing is not independent confirmation of compromise.
Actor ClaimedActor-claimed victim evidence. This listing is not independent confirmation of compromise.
Actor ClaimedActor-claimed victim evidence. This listing is not independent confirmation of compromise.
Actor ClaimedActor-claimed victim evidence. This listing is not independent confirmation of compromise.
Actor ClaimedActor-claimed victim evidence. This listing is not independent confirmation of compromise.
Actor ClaimedActor-claimed victim evidence. This listing is not independent confirmation of compromise.
Actor ClaimedActor-claimed victim evidence. This listing is not independent confirmation of compromise.
Actor ClaimedIdentity and attribution
Exact names and tracking identifiers resolve to this canonical profile. Rebrands, affiliations, and overlapping clusters remain separate confidence-rated relationships.
Name map
Loading CVEs, techniques, indicators, malware, victims, and activity...