Also known as: tracked as, Rebecca, Two, 3 of Dark Matter, Project Spy, Cridex, similar to Sliver, Cobalt Strike, consists of multiple components, NoFive, Plat1, Tech Sectors, OILRIG, Flying Kitten, Travnet, SaffronRose, Saffron Rose, AjaxSecurityTeam, Ajax Security Team, Group 26, Sayad, U2DiskWatch, control module, Agrius, HELIX KITTEN
DarkMatter’s modus operandi centers on acquiring high‑privilege footholds by exploiting both public and private networks—often through purchased IP blocks or compromised VPN credentials. Once inside, they deploy a two‑fold strategy: (1) install a suite of backdoors and RATs (e.g., DarkComet, Hi‑Zor, HiddenFace) to maintain remote control, perform credential harvesting, and conduct lateral movement via RDP, SMB, and SSH; and (2) deliver ransomware—most prominently BlackMatter (and variants such as HELLOKITTY)—to encrypt organizational data while exfiltrating a subset beforehand to leverage double‑extortion. The group’s toolkit is heterogeneous, spanning Windows PowerShell scripts, custom C/C++ loaders, Android spyware (e.g., LAMEHUG), and even rootkits targeting UEFI and kernel drivers. They routinely modify system registries, install scheduled tasks, and obscure their presence with obfuscated binaries and legitimate services like ngrok or AnyDesk to create covert persistence channels. Operationally, DarkMatter demonstrates a high tempo of activity—launching campaigns against telecommunications providers, diplomatic missions, and government ministries across Turkey, Iran, Qatar, Ukraine, and beyond. They frequently target systems with exposed VPN/APIs, exploit known CVEs in ESXi, Cisco devices, and industrial controllers, then pivot to backup deletion and firewall manipulation. Their use of cloud sync tools (e.g., Rclone, MEGA) for both exfiltration and staging further illustrates an evolved, multi‑stage delivery pipeline.
Objectives
Targeted Sectors
Targeted Countries / Regions
Executive Summary
DarkMatter—also known as the BlackMatter ransomware group—is a medium‑sophistication criminal gang that blends double‑extortion ransomware with persistent espionage tactics. The actors primarily target critical infrastructure and diplomatic entities in the Middle East, leveraging purchased network access, high‑value Remote Access Trojans (RATs), and advanced credential‑dumping before encrypting files and demanding ransom. Their operations blend financially driven attacks with long‑term data exfiltration campaigns, often using custom loaders, backdoors, and legitimate utility abuse to evade defenses and maintain persistence across Windows, Linux, and macOS systems.
Goals & Targeting
The gang’s primary objective is financial gain through ransomware while maximizing leverage via data theft—hence the widespread adoption of a double‑extortion model. They also appear to conduct long‑term espionage on critical infrastructure, especially in telecom and defense sectors, to acquire intellectual property and strategic information that can be leveraged for future high‑profile attacks or ransom negotiation. Their targeting matrix spans sovereign governments, diplomatic embassies, and large industrial enterprises, reflecting a blend of opportunistic ransomware markets with deliberate geopolitical objectives.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Between 2022 and 2025 DarkMatter has executed at least a dozen documented campaigns, most prominently the "RoadSweep" and "RobbinHood" attacks on governmental networks in Ukraine, Latvia, and Lithuania. They frequently combine ransomware with data‑staging techniques that pre‑exfiltrate sensitive documents to leak sites or cloud buckets before file encryption. Operational tempo is sustained; campaigns often begin with a rapid spike of phishing emails or VPN brute force attempts followed by lateral movement using stolen credentials and exploitation of known CVEs in both on‑premise and virtualized infrastructure. Victim profiles include telecommunications vendors, diplomatic missions, and defense ministries across the Middle East and Eastern Europe, emphasizing high‑impact targets that can command significant ransom payments. Notable patterns: use of purchased IP blocks or compromised VPNs for initial access; a modular backdoor architecture supporting multiple hosts; deployment of custom PowerShell loaders that enable in‑memory execution; and an emphasis on double‑extortion with automated data exfiltration to public cloud services such as Rclone, MEGA, and Dropbox. The group’s campaigns also reveal lateral movement via RDP/SMB/SSH credentials, the use of legitimate monitoring tools (e.g., Teramind) for persistence, and routine disabling or modification of security controls through registry edits or UEFI rootkits.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The intelligence base provides a comprehensive view of DarkMatter’s tactics, techniques, and tools, corroborated by multiple reputable reports and threat‑intel feeds. While core capabilities—ransomware deployment, backdoor persistence, credential theft, and double‑extortion—are well established, details about sector coverage beyond telecom/diplomatic entities remain somewhat ambiguous. There are gaps in precise geographical timelines, the extent of mobile‑platform operations, and the frequency of zero‑day exploitation. Overall confidence is moderate to high for the primary threat profile but lower for granular operational nuances.
No campaigns linked yet.
No observed data linked yet.
3
Techniques
50
Tools
0
Campaigns
40
IOCs
0
Observed Data
2
Tactics