DarkSide Attack Shuts Down U.S. Fuel Pipeline
ID: 4c4ded16-f564-546c-b2a2-1423542287b5
STIX ID: report--4c4ded16-f564-546c-b2a2-1423542287b5
Feed Name: Cyble Blog
Threat Score
**Executive summary:** This report analyzes the DarkSide ransomware and its May 2021 attack against Colonial Pipeline, detailing its human-operated RaaS model, double-extortion behavior, technical operations (VSS/VMVSS disabling, custom file extensions derived from MachineGuid, PowerShell-based shadow copy deletion, mutex usage), observable indicators (file hash and multiple C2 IPs/domains), MITRE ATT&CK mappings, and recommended mitigations to reduce impact.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
