DarkSide Ransomware Returns as BlackMatter After Sudden Shutdown of Operations

Probably the world’s most notorious ransomware gang disappears completely and subsequently reappears with new branding in an attempt to separate themselves from the types of attacks that originally brought them fame.

Darkside was the group behind most of the recent attacks on critical infrastructure companies in the U.S. and even faced scrutiny from the U.S. Government. After being shut down in May, the group announced it would shut down operations. What has turned out to be a law enforcement exercise that recovered most of the bitcoins paid in the attack on Colonial Pipeline, seems to have made a loud statement by the U.S. to the DarkSide folks: stay away from our critical infrastructure.

From the ashes rises BlackMatter – encryption algorithms were the giveaway – a rebranding of DarkSide with a clear message that they are officially not attacking specific types of businesses that would put them back into the same mess. From their BlackMatter website on the dark web:

7-14-21 Image-1

Source: BlackMatter

It appears that even cybercriminal gangs learned their lesson. And, while not giving up their life of crime, they know now to steer clear of targets that will put a cyber target on their back.

Despite the rebranding and new focus, DarkSide/BlackMatter has proven itself to be a dangerous criminal organization with state of the art ransomware capabilities that every organization (including those on the list above!) needs to avoid at all costs.

Recommended Posts