Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors darkangels

Description

Dark Angels is a highly selective ransomware group active since April 2022 that targets a small number of large enterprises — including Johnson Controls — exfiltrating up to 100 TB of data per victim, and secured the largest known single ransom payment of $75 million from a Fortune 50 company in early 2024. 2 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

Dark Angles is a medium-sophistication cybercriminal group specializing in highly selective ransomware attacks targeting large enterprises. They are known for their ability to exfiltrate massive amounts of data (up to 100 TB per victim) and have successfully negotiated the largest single ransom payment ($75 million) from a Fortune 50 company in early 2024. Their operational focus on high-value targets suggests they prioritize organizational gain through lucrative ransom demands.

Goals & Targeting

Dark Angles' primary objectives are financial gain through ransom payments and organizational disruption. They target large enterprises, particularly those in sectors like manufacturing, technology, and finance, where data value is high and recovery costs are significant. Their targeting strategy appears to prioritize both the ability to pay a large ransom and the potential political or reputational impact of a breach. The group's focus on a limited number of high-value targets reflects their criminal business model aimed at maximizing returns with minimal exposure.

Enhanced Description

Dark Angles is a sophisticated ransomware group that emerged in April 2022 and has since targeted highly valuable enterprises, including Johnson Controls and a Fortune 50 company. Unlike many other ransomware groups, Dark Angles operates with a high degree of selectivity, focusing on large corporations rather than indiscriminate attacks. Their modus operandi involves extensive data exfiltration prior to deploying ransomware, which not only increases the pressure on victims but also demonstrates their technical capabilities. The group is known for its professionalism in negotiation and has achieved significant financial gains through their operations. Dark Angles' focus on high-value targets indicates a strategic approach to maximizing returns while minimizing operational risks. Their activities represent a growing trend of cybercriminal groups prioritizing quality over quantity in their victim selection, aligning with the broader evolution of ransomware tactics.

Key Capabilities

  • Highly selective targeting of large enterprises
  • Massive data exfiltration (up to 100 TB)
  • Professional negotiation for ransom payments
  • Advanced persistent threat (APT) tactics for data theft
  • Ransomware deployment for financial gain

MITRE ATT&CK Tactics

Ransomware
Initial Access
Credential Access
Exfiltration
Defense Evasion

ATT&CK Techniques

T1059.003 - Process Injection: In-memory code injection
T1566.001 - Ransom Data Encryption: File encryption by ransomware family
T1046 - Network Device Disruption: Potential use of network tools for lateral movement or data extraction
T1572 - Adversary-in-the-Cloud: Command and Control (C2) communication via cloud services

Software / Tooling

Custom ransomware family
Cobalt Strike (potential use for initial access)
Lateral movement tools (e.g., SMB or RDP-based tools)
Encryption tools (Emsisoft, REvil)

Campaigns & Victims

Dark Angles has been highly active in early 2024, with a notable campaign against a Fortune 50 company resulting in $75 million ransom payment. They appear to operate with a slower operational tempo compared to volume-focused groups but compensate by targeting higher-value victims. Their campaigns are characterized by thorough data exfiltration prior to ransomware deployment, demonstrating their focus on maximizing damage and negotiate power. Past operations include attacks on Johnson Controls and other high-profile enterprises in the manufacturing sector.

IOC Patterns

  • Exfiltration of massive volumes of data (100 TB+)
  • Ransomware payload delivery via encrypted C2 communication
  • Lateral movement within corporate networks using SMB/RDP protocols
  • Data staging for exfiltration using cloud storage or web-based tools
  • Use of custom ransomware with encryption capabilities

Recommended Actions

  • Implement endpoint detection and response (EDR) solutions to identify malicious processes related to known ransomware families.
  • Enforce multi-factor authentication (MFA) for critical systems and data repositories.
  • Conduct regular backups and ensure they are stored offline and encrypted.
  • Monitor network traffic for异常加密通信 or unusual patterns indicating exfiltration activity.
  • Train employees to recognize phishing attempts and suspicious emails, as these may be used as entry vectors.
  • Segment networks to limit lateral movement opportunities for attackers.
  • Deploy anti-malware solutions capable of detecting custom ransomware variants.
  • Establish a formal incident response plan with specific procedures for responding to ransomware attacks.

Suggested Tags

APT
Ransomware
Financial Crime
High-Tech Crime

Confidence Assessment

High confidence in the existence and operational profile of Dark Angles based on their notoriety and significant financial gains. However, the precise tactics and specific tools used (e.g., exact malware binaries or detailed TTPs) remain less fully documented due to limited publicly available intelligence. Additionally, there is some uncertainty regarding their long-term goals and potential for evolving into a more state-backed entity.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
APT
Financial Crime
High-Tech Crime

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.