logo

DarkSide Attack Shuts Down U.S. Fuel Pipeline

ID: 4c4ded16-f564-546c-b2a2-1423542287b5

STIX ID: report--4c4ded16-f564-546c-b2a2-1423542287b5

Feed Name: Cyble Blog

Threat Score
80/100

Date Published: 2025-05-12

Date Updated: 2026-07-16

...
...

**Executive summary:** This report analyzes the DarkSide ransomware and its May 2021 attack against Colonial Pipeline, detailing its human-operated RaaS model, double-extortion behavior, technical operations (VSS/VMVSS disabling, custom file extensions derived from MachineGuid, PowerShell-based shadow copy deletion, mutex usage), observable indicators (file hash and multiple C2 IPs/domains), MITRE ATT&CK mappings, and recommended mitigations to reduce impact.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.