Home/Threat Actor/DarkSide / BlackMatter
Threat Actor

DarkSide / BlackMatter

darkside_blackmatter · russia_speaking_organized_cybercrime · active since 2020-08

DarkSide / BlackMatter (UNC2628, UNC2659, UNC2465.

Storm-0444; also Russia-speaking-organized-cybercrime cluster widely attributed to overlapping operator membership across the DarkSide era August 2020 to May 2021 and the BlackMatter era July 2021 to November 2021) was a ransomware-as-a-service operation that executed the May 7, 2021 Colonial Pipeline compromise (one of the most operationally consequential ransomware attacks against US critical infrastructure in history, causing multi-day East Coast fuel-supply disruption and prompting US federal emergency declarations covering 17 states), used a signature custom Salsa20-matrix encryption implementation reused essentially unchanged between the DarkSide and BlackMatter brand eras (canonical Emsisoft / Fabian Wosar technical attribution), and is widely analyzed as genealogically continuous with the December 2021 ALPHV/ BlackCat ransomware-as-a-service operation that succeeded it under overlapping operator membership.

russia_speaking_organized_cybercrime confidence: high 18 aliases MITRE ATT&CK G0046 ↗

Profile

DarkSide and BlackMatter are two operationally-sequential ransomware-as-a-service (RaaS) brand names that almost certainly represent the same Russia-speaking organized- cybercrime operator membership operating across two distinct operational eras: DarkSide (August 2020 to May 2021, shut down following the Colonial Pipeline operation) and BlackMatter (July 2021 to November 2021, emerged with a revised exclusions list explicitly designed to avoid the critical-infrastructure attention that led to DarkSide's shutdown, and itself shut down in November 2021 following sustained law-enforcement pressure). The DarkSide-to- BlackMatter genealogical link is established to high technical confidence by Emsisoft, Mandiant, Recorded Future, Flashpoint, Trend Micro, Symantec, and BleepingComputer through reverse-engineering of BlackMatter decryptor samples showing essentially unchanged reuse of DarkSide's signature custom Salsa20 matrix encryption-routine implementation and RSA-key-management code.

Subsequent industry analysis has further traced the DarkSide/BlackMatter operator membership through to the December 2021 launch of the ALPHV/BlackCat ransomware-as-a-service operation, making DarkSide
  • BlackMatter.
  • ALPHV/BlackCat one of the most operationally significant ransomware genealogical chains of the 2020-2024 era. The ALPHV/BlackCat operation is curated separately in this corpus as alphv_blackcat.yaml; DarkSide and BlackMatter are consolidated under this single YAML because the operational eras are short, sequential, and shared a sufficiently-similar operational model that a single curated profile most efficiently represents the cluster. Operationally DarkSide and BlackMatter ran on the standard Russia-speaking-organized-cybercrime RaaS model in which core operators developed the ransomware payload, maintained the affiliate-administration panel, the data-leak site, and the payment-processing-and-laundering infrastructure, and recruited screened affiliates to execute compromises in exchange for revenue-sharing (DarkSide affiliate cut: 25 percent for ransoms under US$500,000 declining to 10 percent for ransoms over US$5 million). Mandiant identified at least five distinct DarkSide affiliate clusters with three publicly named (UNC2628, UNC2659, UNC2465). UNC2628 used Cobalt Strike Beacon as its primary post-compromise toolkit, Mimikatz for credential theft, and operationally had a median dwell time of approximately two to three days from initial access to ransomware deployment. UNC2659 was distinguished by use of TeamViewer for persistence. UNC2465, the oldest DarkSide- affiliate cluster, was distinguished by use of the PowerShell- based .NET backdoor SMOKEDHAM. Median DarkSide dwell time across the affiliate ecosystem was approximately 45 days, with some affiliates remaining in victim environments for up to 88 days during which they performed extensive reconnaissance, lateral movement, and data exfiltration prior to ransomware deployment. All DarkSide affiliates targeted data-theft-and-encryption double-extortion operations: data was exfiltrated to attacker-controlled cloud storage (Mega, privacyfocused VPS providers) prior to ransomware encryption, and the data-leak site published victim names and progressive data samples to pressure ransom payment. The Colonial Pipeline operation of May 7, 2021 is the operationally most consequential ransomware operation against US critical-infrastructure in history to that date and remains a defining case study for ransomware-against- critical-infrastructure operational impact, US-government response, and US-Russia diplomatic engagement on organized-cybercrime safe-haven. Colonial Pipeline Company, operator of the largest US refined-fuel pipeline transporting approximately 45 percent of US East Coast fuel consumption, discovered the DarkSide ransomware compromise on May 7, 2021, voluntarily shut down pipeline operations to prevent OT- network compromise, paid an approximately US$4.4 million Bitcoin ransom on May 7 to obtain a DarkSide decryption key, and resumed pipeline operations on May 12, 2021. The operation caused multi-day fuel-supply disruption across the US East Coast, panic-buying, regional fuel shortages, US federal emergency declarations covering 17 states and DC, President Biden's May 12, 2021 cybersecurity executive order, and explicit White House public statements raising the question of Russian state safe-haven for the cluster. The FBI subsequently recovered approximately 63.7 of the 75 Bitcoin (~US$2.3 million) ransom payment through an operation against DarkSide-controlled cryptocurrency wallets announced June 7, 2021 by US DOJ, establishing one of the earliest US-government operational precedents for cryptocurrency-recovery-as-disruption-against-ransomware. DarkSide announced operational shutdown on May 13, 2021, six days after the Colonial Pipeline operation, citing "pressure from the US" and loss of operational infrastructure. The BlackMatter operation that emerged on July 19, 2021 on Russian-language cybercrime forums was structured almost identically to DarkSide with the addition of explicit critical-infrastructure-exclusion rules (oil-and-gas pipelines, oil refineries, hospitals, government, education) directly responsive to the Colonial Pipeline-induced shutdown. BlackMatter operationally ran for approximately four months (July to November 2021) with notable named victims including US agricultural-cooperative NEW Cooperative Inc. (Iowa, September 2021), Crystal Valley Cooperative (Minnesota, September 2021), broadcasting-software provider Marketron (September 2021), and Japanese imaging-equipment-manufacturer Olympus Corporation (September 2021). The September 2021 US-agricultural-cooperative compromises during the US fall harvest season demonstrated that BlackMatter affiliates were not honoring the publicly-stated critical-infrastructure- exclusion rules and prompted the October 18, 2021 CISA/FBI/ NSA AA21-291A joint cybersecurity advisory on BlackMatter tradecraft and indicators-of-compromise. BlackMatter announced operational shutdown on November 1-3, 2021 citing "pressure from the authorities," approximately coinciding with the November 2021 international Operation GoldDust law-enforcement activity against REvil affiliates and US DOJ indictment of REvil-affiliated operators. Technically, the DarkSide and BlackMatter ransomware implementations are notable for: (a) signature use of a custom Salsa20-stream-cipher matrix implementation reused essentially unchanged between DarkSide and BlackMatter (Emsisoft / Fabian Wosar canonical technical attribution); (b) RSA key management for per-file Salsa20 key wrapping; (c) cross-platform variants targeting Windows, Linux, and VMware ESXi hypervisor environments, the ESXi variant enabling rapid encryption of entire virtualized data centers via shared-datastore access (CVE-2019-5544 and CVE-2020-3992 ESXi RCE vulnerabilities used by UNC2628 against Colonial Pipeline ESXi infrastructure); (d) embedded system-language geolocation check excluding execution on hosts configured with any of twelve CIS-country languages plus Syrian Arabic (standard Russia-speaking-organized- cybercrime signature). The DarkSide and BlackMatter operational and technical patterns are operationally significant because they were heavily reused by DarkSide/BlackMatter affiliates after the operational shutdowns (affiliates rotating to operate under other RaaS brands including subsequently ALPHV/BlackCat, Hive, and LockBit), making DarkSide/BlackMatter tradecraft patterns operationally relevant against affiliates active under other brand names long after the original cluster shutdowns. The DarkSide-and-BlackMatter case is also operationally significant as a defining case study for US-government disruption-of-organized-cybercrime operations against Russia-speaking RaaS. The May 2021 Colonial Pipeline operation established that US-government infrastructure- disruption, cryptocurrency-recovery, and diplomatic- engagement responses to high-profile critical-infrastructure ransomware operations could effectively shut down operationally-running RaaS programs in short timescales (DarkSide shutdown six days after Colonial; BlackMatter shutdown approximately four months after launch under sustained US-government and partner-nation pressure). Subsequent US-government disruption operations against REvil (October-November 2021), Hive (January 2023), ALPHV/ BlackCat (December 2023), and LockBit (Operation Cronos, February 2024) operationally build on the precedents established in the DarkSide and BlackMatter disruption operations. The DarkSide and BlackMatter case studies together constitute the operationally-defining historical example of the Russia-speaking-organized-cybercrime ransomware ecosystem's responsiveness to sustained US-government and partner-nation operational pressure.

Aliases

18
darksidedark sideblackmatterblack matterdarkside ransomwareblackmatter ransomwaredarkside_raasblackmatter_raasunc2628unc2659unc2465storm-0444storm0444storm-0444_darksidecarbon spidergold waterfalldark_sideblack_matter

MITRE ATT&CK aliases

5
Additional names MITRE lists for G0046.
FIN7GOLD NIAGARAITG14ELBRUSSangria Tempest

Notable Campaigns

10
2021-2024ALPHV/BlackCat Ransomware-as-a-Service Genealogical Continuation (December 2021 onward)
2021CompuCom IT Services Ransomware Attack (March 2021)
2021Brenntag SE Specialty Chemicals Ransomware Attack (May 2021)
2021Colonial Pipeline Company Ransomware Attack (May 7-12, 2021)
2021DarkSide Operational Shutdown Announcement (May 13-14, 2021)
2021BlackMatter Ransomware-as-a-Service Emergence (July 19, 2021)
2021BlackMatter Operations Including Olympus, Marketron, NEW Cooperative (September-October 2021)
2021CISA AA21-291A Joint Advisory on BlackMatter Ransomware (October 18, 2021)
2021BlackMatter Operational Shutdown Announcement (November 1-3, 2021)
2020DarkSide Ransomware-as-a-Service Operational Emergence (August 2020)

Attribution & Reporting

Attributed by
FBIUS Cybersecurity and Infrastructure Security Agency (CISA)US Department of JusticeUS Department of EnergyUS Department of the TreasuryWhite HouseMandiantFireEye (legacy Mandiant)Microsoft Threat Intelligence CenterCrowdStrikeRecorded FutureSecureWorksSophosTrend MicroTrellixKaspersky GReATSymantec / BroadcomFlashpointEllipticChainalysisBleepingComputerEmsisoftCybereason
Key reporting
reportFBI + CISA AA21-131A: DarkSide Ransomware: Best Practices for Preventing Business Disruption from Ransomware Attacks (May 11, 2021), DarkSide-era US-government formal attribution
reportFBI + CISA + NSA AA21-291A: BlackMatter Ransomware (October 18, 2021), BlackMatter-era US-government formal attribution
reportUS Department of Justice: Department of Justice Seizes $2.3 Million in Cryptocurrency Paid to the Ransomware Extortionists Darkside (June 7, 2021), formal ransom-recovery announcement
reportMandiant: Shining a Light on DARKSIDE Ransomware Operations (May 2021), five affiliate clusters identified (UNC2628, UNC2659, UNC2465)
reportRecorded Future: BlackMatter Likely Connected to Both DarkSide and REvil (August 2021)
reportBleepingComputer / Fabian Wosar (Emsisoft): DarkSide Ransomware Gang Returns as New BlackMatter Operation (August 1, 2021), canonical technical-genealogical attribution
reportTrend Micro: BlackMatter Ransomware Emerges from the Shadow of DarkSide (August 2021)
reportSymantec / Broadcom Threat Hunter Team: BlackMatter Ransomware (October 2021)
reportSophos 2022 Threat Report, DarkSide / BlackMatter / ALPHV genealogy analysis
reportTrellix / McAfee Advanced Threat Research: Technical Analysis of DarkSide Ransomware (May 2021)
reportSecureWorks Counter Threat Unit: GOLD WATERFALL Profile (DarkSide-adjacent)
reportFlashpoint: BlackMatter Operational Analysis (July-November 2021)
reportCrowdStrike: 2022 Global Threat Report, DarkSide / BlackMatter / ALPHV chapter
reportElliptic: Analysis of DarkSide Bitcoin Laundering and Tracking (May-June 2021)
reportChainalysis: 2021 Ransomware Update, DarkSide and BlackMatter financial-flow analysis
reportKaspersky GReAT: Ransomware Reports 2021, DarkSide/BlackMatter Coverage
reportCybereason: BlackMatter Ransomware Threat Profile (2021)
reportMalpedia Malware Family Profiles: win.darkside and win.blackmatter

Operational

State sponsor

Russia-speaking organized cyber-criminal cluster. The cluster's ransomware payloads contained an embedded geolocation check (system language enumeration) that explicitly avoided execution on hosts whose configured language matched any of the twelve Commonwealth of Independent States (CIS) member or former-member country languages, plus Syrian Arabic. The CIS-language-exclusion check is a standard operational signature of Russia-speaking organized-cybercrime ransomware families and is the strongest operational indicator that the cluster operated from within CIS jurisdictions, almost certainly Russia.

The cluster registered and operated on Russian-language cybercrime forums including XSS and Exploit. No formal state-actor attribution has been asserted by any government cybersecurity authority, but the May 2021 Colonial Pipeline incident prompted senior US government statements explicitly raising the question of whether the Russian state was providing safe-haven to the cluster. The Biden administration subsequently used the DarkSide / Colonial Pipeline case as a centerpiece example in US-Russia diplomatic engagement regarding state responsibility to prevent organized-cybercrime safe-haven.

The DarkSide cluster operationally shut down in May 2021 immediately following the Colonial Pipeline operation, and the BlackMatter cluster, sharing significant code-base genealogy and almost certainly comprising overlapping operator membership, emerged in July 2021 with stated targeting-list exclusions (oil and gas, healthcare, government, education) designed to avoid the critical-infrastructure-impact attention that led to DarkSide's shutdown.

Motivations
financial_ransom, double_extortion_data_theft_and_encryption, ransomware_as_a_service_affiliate_revenue_sharing
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)55/60 · 91%
Analytics (MITRE CAR)31/60 · 51%
Runtime / container (Falco)8/60 · 13%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)13/60 · 21%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

2 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MEGA NZ CLIENTSHARPHOUND
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin