Also known as: tracked as, Thief 1, T1, simply Thief
Dark Project is identified by several aliases—including Thief 1, T1, and simply Thief—and operates as a criminal enterprise with medium sophistication. The group’s core motivation is financial gain, achieved through ransomware payouts and the sale of exfiltrated data. Their operational history dates to late 2024, encompassing sectors such as manufacturing, logistics, professional services, transportation, defense, education, healthcare, IT, gaming, and finance across the United States and Great Britain. TTP analysis shows that Dark Project initiates campaigns primarily through spear‑phishing emails or exploitation of exposed Remote Desktop Services. Once inside a network, they execute rapid lateral movement using legitimate tools (e.g., Empire) to expand their foothold. The group then amasses large volumes of data—including PII, employee records, payroll documents, and internal PDFs—before encrypting systems with ransomware families such as Clop or Qilin. A key differentiator is the dual‑extortion model: apart from demanding ransom payments, they threaten public release via a proprietary leak site equipped with countdown timers. Campaign evidence includes significant data exfiltrations (e.g., nearly 600 GB from TSC Logistics) and the publication of unredacted PDFs on their own leak platform. Victims comprise a mix of manufacturing firms, logistics companies, healthcare providers, educational institutions, defense contractors, financial services, and gaming studios. The group’s operational tempo is rapid; multiple attacks are observed within weeks, showing an ability to repeat phishing or RDP exploitation cycles efficiently. In intelligence context, Dark Project operates alongside other notorious ransomware actors but distinguishes itself through the combination of malware delivery, exfiltration magnitude, leak‑site monetisation, and use of public countdowns to pressure victims. Their choice of targets reflects a focus on entities holding large amounts of sensitive personal or operational data, ensuring both ransom value and bargaining leverage. Overall, the threat profile depicts a financially driven actor capable of orchestrating sophisticated, multi‑phase attacks that blend technical proficiency with strategic extortion tactics.
Objectives
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Dark Project (aka Thief 1/T1) is a mid‑sophistication criminal ransomware group that emerged in late 2024 and targets high‑profile sectors across the US and UK. The threat actors combine phishing or Remote Desktop Service exploitation with rapid lateral movement to exfiltrate large volumes of sensitive data, then employ a dual‑extortion model by threatening publication of stolen files on their own leak sites. Their campaigns demonstrate operational agility, frequent ransomware deliveries (e.g., Clop variants), and an emphasis on monetising stolen documents through leak‑site sales.
Goals & Targeting
Dark Project’s strategic objectives revolve around maximizing financial gain through ransomware payouts and monetising exfiltrated data. The group targets organizations that maintain sizable repositories of personal information or proprietary operational documents—such as logistics planners, manufacturing schematics, payroll databases, and healthcare patient records—to create a high‑value leverage point for dual extortion. Their sector selection (manufacturing, transportation, defense, education, healthcare, IT, gaming) reflects an opportunistic approach aimed at organizations where data breaches can cause regulatory penalties and reputational harm, thereby enhancing the threat actor’s bargaining power.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Dark Project exhibits a high operational tempo, with multiple large‑scale campaigns occurring within days or weeks of one another. Victims span manufacturing, logistics, education, healthcare, defense, finance, and gaming—all sectors capable of producing substantial data sets for extortion. The group consistently follows the initial access–lateral movement–data exfiltration–encryption protocol, culminating in a dual‑extortion demand that includes threat releases on leak sites with countdown timers. Their notable operations—such as the TSC Logistics infiltration (≈600 GB) and numerous other campaigns targeting similar industry sectors—demonstrate an emphasis on monetising both ransom payouts and data sales via publicly accessible leak platforms.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The information about Dark Project’s tactics, techniques, and campaign patterns is derived from multiple public threat reports and shows consistent evidence of phishing-based initial access, Remote Desktop exploitation, large‑scale data exfiltration, and dual extortion. Confidence in these core TTPs is high due to repeated observation across at least five separate incidents. However, attribution certainty remains limited—while the group’s name is referenced publicly, there is no unequivocal forensic backing linking all reported attacks to a single actor. Additionally, some tool references (e.g., certain variants of Malware families) lack definitive validation, and details about persistence mechanisms or full malware chain remain sparse. Data gaps include: concrete evidence of specific backdoor deployments, exhaustive inventory of command‑and‑control infrastructure, thorough mapping between ransomware variants used, and detailed post‑exfiltration leak‑site operations. Addressing these gaps would strengthen overall confidence in the threat landscape assessment.
No observed data linked yet.
6
Techniques
24
Tools
19
Campaigns
36
IOCs
0
Observed Data
4
Tactics