Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors darkrace

Description

DarkRace is a ransomware variant that surfaced in mid-2023 sharing strong code similarities with LockBit, employing double-extortion via a dark web leak site, but remained a minor player with fewer than 15 posted victims in its first half-year. Known victims: 10

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

DarkRace is a ransomware actor that emerged in mid-2023, operational until at least early June 2023. The group employs double extortion tactics, using encryption and threatening to leak stolen data unless ransoms are paid. Despite its limited history with fewer than 15 victims to date, DarkRace poses a growing concern due to its evolving ransomware operations and financial motives.

Goals & Targeting

DarkRace's primary objectives are financial gain through ransom payments. It targets organizations with accessible data storage systems, focusing on sectors where downtime or data loss would result in significant business disruption. Victims to date have included mid-sized businesses across multiple industries, reflecting a pragmatic approach to maximizing revenue while minimizing operational overhead.

Enhanced Description

DarkRace is a ransomware variant observed first in May 2023, sharing code similarities with LockBit. It has employed double extortion tactics, encrypting victims' data and threatening data leakage on a dark web site if ransoms are not paid. The group primarily targets organizations across various sectors, focusing on those with accessible or valuable data. With fewer than 15 known victims in its first months of operation, DarkRace remains a relatively small player but demonstrates capability to execute successful ransomware campaigns. The actor's operational timeline suggests moderate planning and execution, aligning with its 'medium' sophistication level.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
May 30, 2023
Last Seen
Jun 9, 2023
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.