Dark Angels is a highly selective ransomware group active since April 2022 that targets a small number of large enterprises — including Johnson Controls — exfiltrating up to 100 TB of data per victim, and secured the largest known single ransom payment of $75 million from a Fortune 50 company in early 2024. 2 ransom note(s) on file
Objectives
Executive Summary
Dark Angles is a medium-sophistication cybercriminal group specializing in highly selective ransomware attacks targeting large enterprises. They are known for their ability to exfiltrate massive amounts of data (up to 100 TB per victim) and have successfully negotiated the largest single ransom payment ($75 million) from a Fortune 50 company in early 2024. Their operational focus on high-value targets suggests they prioritize organizational gain through lucrative ransom demands.
Goals & Targeting
Dark Angles' primary objectives are financial gain through ransom payments and organizational disruption. They target large enterprises, particularly those in sectors like manufacturing, technology, and finance, where data value is high and recovery costs are significant. Their targeting strategy appears to prioritize both the ability to pay a large ransom and the potential political or reputational impact of a breach. The group's focus on a limited number of high-value targets reflects their criminal business model aimed at maximizing returns with minimal exposure.
Enhanced Description
Dark Angles is a sophisticated ransomware group that emerged in April 2022 and has since targeted highly valuable enterprises, including Johnson Controls and a Fortune 50 company. Unlike many other ransomware groups, Dark Angles operates with a high degree of selectivity, focusing on large corporations rather than indiscriminate attacks. Their modus operandi involves extensive data exfiltration prior to deploying ransomware, which not only increases the pressure on victims but also demonstrates their technical capabilities. The group is known for its professionalism in negotiation and has achieved significant financial gains through their operations. Dark Angles' focus on high-value targets indicates a strategic approach to maximizing returns while minimizing operational risks. Their activities represent a growing trend of cybercriminal groups prioritizing quality over quantity in their victim selection, aligning with the broader evolution of ransomware tactics.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Dark Angles has been highly active in early 2024, with a notable campaign against a Fortune 50 company resulting in $75 million ransom payment. They appear to operate with a slower operational tempo compared to volume-focused groups but compensate by targeting higher-value victims. Their campaigns are characterized by thorough data exfiltration prior to ransomware deployment, demonstrating their focus on maximizing damage and negotiate power. Past operations include attacks on Johnson Controls and other high-profile enterprises in the manufacturing sector.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in the existence and operational profile of Dark Angles based on their notoriety and significant financial gains. However, the precise tactics and specific tools used (e.g., exact malware binaries or detailed TTPs) remain less fully documented due to limited publicly available intelligence. Additionally, there is some uncertainty regarding their long-term goals and potential for evolving into a more state-backed entity.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics