Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors darkmatter

Also known as: tracked as, Rebecca, Two, 3 of Dark Matter, Project Spy, Cridex, similar to Sliver, Cobalt Strike, consists of multiple components, NoFive, Plat1, Tech Sectors, OILRIG, Flying Kitten, Travnet, SaffronRose, Saffron Rose, AjaxSecurityTeam, Ajax Security Team, Group 26, Sayad, U2DiskWatch, control module, Agrius, HELIX KITTEN

Description

DarkMatter’s modus operandi centers on acquiring high‑privilege footholds by exploiting both public and private networks—often through purchased IP blocks or compromised VPN credentials. Once inside, they deploy a two‑fold strategy: (1) install a suite of backdoors and RATs (e.g., DarkComet, Hi‑Zor, HiddenFace) to maintain remote control, perform credential harvesting, and conduct lateral movement via RDP, SMB, and SSH; and (2) deliver ransomware—most prominently BlackMatter (and variants such as HELLOKITTY)—to encrypt organizational data while exfiltrating a subset beforehand to leverage double‑extortion. The group’s toolkit is heterogeneous, spanning Windows PowerShell scripts, custom C/C++ loaders, Android spyware (e.g., LAMEHUG), and even rootkits targeting UEFI and kernel drivers. They routinely modify system registries, install scheduled tasks, and obscure their presence with obfuscated binaries and legitimate services like ngrok or AnyDesk to create covert persistence channels. Operationally, DarkMatter demonstrates a high tempo of activity—launching campaigns against telecommunications providers, diplomatic missions, and government ministries across Turkey, Iran, Qatar, Ukraine, and beyond. They frequently target systems with exposed VPN/APIs, exploit known CVEs in ESXi, Cisco devices, and industrial controllers, then pivot to backup deletion and firewall manipulation. Their use of cloud sync tools (e.g., Rclone, MEGA) for both exfiltration and staging further illustrates an evolved, multi‑stage delivery pipeline.

Goals & Targeting

Objectives

Ransomware
Financial Gain

Targeted Sectors

Government
Financial services
Defense
Telecommunications
Energy
Non profit
Healthcare
Manufacturing
Education
Media
Critical infrastructure
Transportation
Aerospace
Utilities
Retail
Hospitality
Information technology
Pharmaceutical
Oil gas
Mining
Gaming
Think tank
Maritime
Chemical
Aviation
Legal services
Nuclear

Targeted Countries / Regions

US
CN
RU
IN
UA
JP
KR
GB
BR
PL
AU
VN
MX
IL
IR
CA
TW
PK
AE
SA
DE
ES
KP
TR
SY
IT
KZ
FR
BY
SG
NL
AZ
LB

AI Analysis

Grounded in web research
· analyzed in 82 chunks · 5 days ago

Executive Summary

DarkMatter—also known as the BlackMatter ransomware group—is a medium‑sophistication criminal gang that blends double‑extortion ransomware with persistent espionage tactics. The actors primarily target critical infrastructure and diplomatic entities in the Middle East, leveraging purchased network access, high‑value Remote Access Trojans (RATs), and advanced credential‑dumping before encrypting files and demanding ransom. Their operations blend financially driven attacks with long‑term data exfiltration campaigns, often using custom loaders, backdoors, and legitimate utility abuse to evade defenses and maintain persistence across Windows, Linux, and macOS systems.

Goals & Targeting

The gang’s primary objective is financial gain through ransomware while maximizing leverage via data theft—hence the widespread adoption of a double‑extortion model. They also appear to conduct long‑term espionage on critical infrastructure, especially in telecom and defense sectors, to acquire intellectual property and strategic information that can be leveraged for future high‑profile attacks or ransom negotiation. Their targeting matrix spans sovereign governments, diplomatic embassies, and large industrial enterprises, reflecting a blend of opportunistic ransomware markets with deliberate geopolitical objectives.

Enhanced Description

Key Capabilities

  • Deployable ransomware (BlackMatter, HELLOKITTY, HermeticWiper)
  • Backdoor persistence via custom loaders
  • Keylogging and screen capture via RATs (DarkComet, Hi‑Zor, HiddenFace)
  • Credential dumping and lateral movement (LSASS, SMB/ RDP/ SSH)
  • Use of legitimate tunneling tools (ngrok, AnyDesk, Teramind, Time Doctor)
  • Rootkit and UEFI bootkit installation
  • Data exfiltration via cloud services (Rclone, MEGA, Dropbox)
  • Scheduled task and registry-based persistence
  • Phishing/spear‑phishing with malicious Office macros or VBS
  • Exploit of known CVEs in VPNs, ESXi, and industrial devices

MITRE ATT&CK Tactics

Impact
Initial Access
Execution
Command and Control
Credential Access
Exfiltration
Collection
Defense Evasion
Persistence
Lateral Movement
Privilege Escalation
Discovery
Remote Services

ATT&CK Techniques

T1486
T1189
T1071
T1566.001
T1003
T1041
T1056.001
T1113
T1110
T1021.001
T1059.001
T1203
T1086
T1105
T1074
T1060
T1027
T1112
T1077
T1078
T1529
T1547.003
T1053.005
T1036
T1548.002

Software / Tooling

BlackMatter ransomware
HELLOKITTY
HermeticWiper
DarkComet RAT
Hi‑Zor
HiddenFace
HilalRAT
HotCroissant
Cobalt Strike BEACON
Ngrok
AnyDesk
Teramind
Time Doctor
Psexec
WinRM

Campaigns & Victims

Between 2022 and 2025 DarkMatter has executed at least a dozen documented campaigns, most prominently the "RoadSweep" and "RobbinHood" attacks on governmental networks in Ukraine, Latvia, and Lithuania. They frequently combine ransomware with data‑staging techniques that pre‑exfiltrate sensitive documents to leak sites or cloud buckets before file encryption. Operational tempo is sustained; campaigns often begin with a rapid spike of phishing emails or VPN brute force attempts followed by lateral movement using stolen credentials and exploitation of known CVEs in both on‑premise and virtualized infrastructure. Victim profiles include telecommunications vendors, diplomatic missions, and defense ministries across the Middle East and Eastern Europe, emphasizing high‑impact targets that can command significant ransom payments. Notable patterns: use of purchased IP blocks or compromised VPNs for initial access; a modular backdoor architecture supporting multiple hosts; deployment of custom PowerShell loaders that enable in‑memory execution; and an emphasis on double‑extortion with automated data exfiltration to public cloud services such as Rclone, MEGA, and Dropbox. The group’s campaigns also reveal lateral movement via RDP/SMB/SSH credentials, the use of legitimate monitoring tools (e.g., Teramind) for persistence, and routine disabling or modification of security controls through registry edits or UEFI rootkits.

IOC Patterns

  • Double‑extortion ransomware file‑encryption indicators
  • Keylogging and screenshot payload markers
  • RAT beacon traffic via custom protocols or ngrok tunnels
  • Credential dumping footprints (lsass memory, sam dump)
  • Scheduled task persistence signatures
  • Rootkit installation artifacts (UEFI, HIDEDRV)
  • Cloud‑based exfiltration to Rclone/MEGA endpoints
  • VPN brute–force login spikes

Recommended Actions

  • Implement and monitor privileged account activity using least‑privilege controls and MFA to mitigate silent privilege escalation.
  • Deploy endpoint detection & response systems that alert on in‑memory PowerShell execution, registry modifications (Run keys, InprocServer32) and scheduled task creation for persistence. "Enforce strict macro security"—block Office attachments with scripts or VBA, deploy mail filtering and attachment sandboxing to detect spear‑phishing. Use application whitelisting and restrict the use of legitimate remote‑management tools such as AnyDesk/Teramind; log all installations and enforce vendor approval workflows. Implement network segmentation and tightly control VPN/SMB/SSH access, monitor for brute‑force attacks against these services, and enable multi‑factor authentication where possible. Adopt robust backup and restore plans across physical, virtualized and cloud ecosystems, including snapshot protection and immutable backups to nullify data wipe and ransomware threats. Deploy web filtering or sandboxing solutions that detect malicious URLs associated with known loader sites (e.g., Malvertising, fake App installers) and enforce a strict policy on the use of third‑party cloud storage for exfiltration. Enforce strong patch management across all platforms—especially ESXi hosts, Cisco appliances, and industrial control systems—to block exploitation of known CVEs used by this group.

Suggested Tags

ransomware
double-extortion
telecommunications
diplomatic-missions
middle-eastern-targets
credential-dumping
remote-access-tools
backdoor
mobile-malware
iot-targeting
industrial-control-systems
cloud-exfiltration
rootkit
scheduled-task-persistence
vulnerability-exploitation

Confidence Assessment

The intelligence base provides a comprehensive view of DarkMatter’s tactics, techniques, and tools, corroborated by multiple reputable reports and threat‑intel feeds. While core capabilities—ransomware deployment, backdoor persistence, credential theft, and double‑extortion—are well established, details about sector coverage beyond telecom/diplomatic entities remain somewhat ambiguous. There are gaps in precise geographical timelines, the extent of mobile‑platform operations, and the frequency of zero‑day exploitation. Overall confidence is moderate to high for the primary threat profile but lower for granular operational nuances.

ATT&CK Techniques

Initial Access
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. https://www.netsecurity.com/blackmatter-ransomware-analysis/ — Cited by AI analysis.
  2. https://www.emsisoft.com/en/blog/39121/ransomware-profile-black-matter/ — Cited by AI analysis.
  3. https://www.darktrace.com/blog/blackmatters-smash-and-grab-tactics-and-the-need-for-respond — Cited by AI analysis.
  4. https://thehackernews.com/2023/07/how-to-apply-mitre-att-to-your.html — Cited by AI analysis.
  5. https://attack.mitre.org/software/ — Cited by AI analysis.
  6. github.com — Cited by web research for: Tech Sectors
  7. www.sentinelone.com — Cited by web research for: Singularity
  8. cloud.google.com — Cited by web research for: WarLock
  9. attack.mitre.org — Cited by web research for: vnd.openxmlformats-officedocument.spreadsheetml.sheet

Intel Summary

3

Techniques

50

Tools

0

Campaigns

40

IOCs

0

Observed Data

2

Tactics

Tags

APT
ransomware
financial-motivation
sector-specific-attacks
espionage
critical-infrastructure-targeting
double-extortion
telecommunications
diplomatic-missions
middle-eastern-targets
credential-dumping
remote-access-tools
backdoor
mobile-malware
iot-targeting
industrial-control-systems
cloud-exfiltration
rootkit
scheduled-task-persistence
vulnerability-exploitation

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Country of Origin
China (CN)
Confidence
80%
Added
Jul 23, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.