logo

Lessons Learned from Telemetry Analysis of DarkSide Affiliate Exfiltration Operations

ID: 7e49674e-bf97-5388-9a5a-9ca00154c161

STIX ID: report--7e49674e-bf97-5388-9a5a-9ca00154c161

Feed Name: Dragos Blog

Threat Score
80/100

Date Published: 2021-05-26

Date Updated: 2026-04-27

...
...

This analysis details a DarkSide RaaS affiliate campaign that executed coordinated data exfiltration via SFTP/SSH to a leased VPS and likely deployed DarkSide ransomware to multiple victims — notably Colonial Pipeline and Brenntag subsidiaries — resulting in significant operational impact and multi-million-dollar ransom payments; telemetry showed large-volume transfers, Tor-based communications likely used for C2 or ransom negotiation, and opportunities for mitigation via DLP and web filtering.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.