Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors darkpower

Description

Dark Power emerged in January 2023 as a ransomware group written in the Nim programming language, claiming 10 victims across eight countries within its first month across agriculture, education, healthcare, IT, and manufacturing sectors, demanding $10,000 ransoms payable in Monero. Known victims: 10 1 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

Dark Power is a medium-sophistication ransomware group targeting multiple sectors for financial gain through Monero-based ransoms.

Goals & Targeting

Dark Power targets sectors with potentially less robust defenses to maximize financial gain. The diverse attack surface indicates an effort to exploit varied vulnerabilities for rapid victim acquisition and ransom collection.

Enhanced Description

Dark Power emerged in January 2023 as a Nim-based ransomware group, rapidly targeting industries including agriculture, education, healthcare, IT, and manufacturing. Within the first month, they attacked ten victims across eight countries, demanding $10,000 in Monero. Their initial operations suggest a focus on quick monetization through broad sector targeting.

Key Capabilities

  • Ransomware Deployment
  • Encryption using Nim

Software / Tooling

Nim-based Ransomware

Campaigns & Victims

Dark Power initiated operations in January 2023, quickly affecting a global spread across multiple sectors. Their campaigns demonstrate adaptability and efficiency, focusing on rapid victimization to escalate their operations within a short timeframe.

Recommended Actions

  • Enhance network visibility
  • Implement regular backups
  • Educate employees on phishing
  • Secure remote access

Suggested Tags

ransomware
criminal
financial-gain

Confidence Assessment

Low confidence due to limited historical data and campaign specifics. Further monitoring for long-term patterns and toolset evolution is essential.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Healthcare Targeting
ransomware
criminal
financial-gain

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Mar 11, 2023
Last Seen
Mar 11, 2023
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.