Arab Press

بالشعب و للشعب
Monday, Mar 30, 2026

Infamous DarkSide ransomware reborn as new cyber threat: reports

Infamous DarkSide ransomware reborn as new cyber threat: reports

BlackMatter says it has the 'best features' of Colonial Pipeline hackers DarkSide, plus other kinds of ransomware

A new cyber gang is in town – and tapping into the best features of ransomware used in the Colonial Pipeline attack.

That new gang, BlackMatter, is upfront about its origins, stating that it has "incorporated" the "best features" of DarkSide and two other kinds of ransomware, REvil and Lockbit, according to a statement from the BlackMatter group as noted by cybersecurity company Recorded Future.

DarkSide was identified by the U.S. government as the ransomware responsible for the Colonial Pipeline attack, which resulted in the shutdown of a major pipeline supplying fuel to the U.S. East Coast.

A man leaves a Murrphy Oil gas station as pumps are seen out of gas, Tuesday, May 11, 2021, in Kennesaw, Ga. after Colonial Pipeline halted operations because of a cyberattack.


After the attack, DarkSide posted a statement saying it was ending operations.

Enter BlackMatter, which is now active on cybercrime forums.

"They’re not advertising their ransomware, however; they are recruiting affiliates…who have access to hacked enterprise networks," according to Malwarebytes. The BlackMatter ads state that it's seeking hacked access to corporate networks in Australia, Canada, the UK and the U.S.

Other requirements for corporations they target include revenue of at least $100 million and 500-15,000 hosts in the network, Recorded Future said.

Like other successful ransomware operations, BlackMatter is run as a business, dubbed Ransomware-as-a-service or RaaS, a knockoff of legitimate business models such as SaaS or software-as-a-service.

Cybersecurity news site Bleeping Computer reported attacks are happening already.

On their own site, BlackMatter says it won’t target certain industries including hospitals, critical infrastructure, the defense industry and the government sector, according to Malwarebytes.

That’s similar to past statements from DarkSide.

"Our goal is to make money, and not creating problems for society. From today we introduce moderation and check each company that our partners want to encrypt to avoid social consequences in the future," the DarkSide group said back in May.

But there may be more practical reasons for this. "Almost as if to say that they are keenly aware of the danger that comes from pulling off internationally-recognized attacks," Malwarebytes said.

In June, the Department of Justice said that it had seized Bitcoin valued at approximately $2.3 million from the DarkSide gang. Those funds represented a ransom payment for the Colonial Pipeline ransomware attack.

Newsletter

Related Articles

Arab Press
0:00
0:00
Close
Saudi Arabia Strongly Condemns Attacks on Presidential Residences in Hawler
Saudi Stocks Edge Lower as Tadawul Index Closes Slightly Down
Houthis Enter Expanding Iran Conflict as US Deploys Additional Troops
Iran Seeks Assurances for Regional Allies as Saudi Arabia Presses for Firm Security Guarantees
Iranian Strike Reportedly Destroys $270 Million US E-3 Sentry Aircraft at Saudi Air Base
Iranian Strike on Saudi Base Leaves Ten American Personnel Injured
Ukraine Claims Russia Shared Satellite Intelligence with Iran Ahead of Saudi Base Strike
Pakistan Engages Regional Powers in Diplomatic Talks Over Iran Conflict
Escalating Iran Conflict Brings Renewed Focus to US Military Presence in Saudi Arabia
Iranian Strike Targets Saudi Airbase, Damaging Key US Military Assets
Modi and Saudi Crown Prince Emphasise Secure Shipping Routes in Talks on West Asia Conflict
Dallas-Based Company Secures One Billion Dollar Hotel Development Deal in Saudi Arabia
Zelensky Secures Defence Cooperation Deals with Gulf States During Strategic Regional Tour
Trump Calls on Saudi Arabia to Join Abraham Accords in Push for Expanded Middle East Cooperation
Trump Balances Humor and Praise in Remarks on Saudi Crown Prince
Saudi Arabia’s Strategic Pipeline Reaches Seven Million Barrel Capacity to Bypass Hormuz
Rubio Signals U.S. Could Conclude Iran Conflict Within Weeks as Air Campaign Intensifies
More Than a Dozen U.S. Soldiers Injured in Saudi Base Attack as Iran-Backed Houthis Expand Conflict
Iranian Strike on US Base in Saudi Arabia Injures Troops and Damages Aircraft
Pakistan to Convene Regional Talks with Saudi Arabia, Turkey and Egypt Amid Iran War Diplomacy
Ukraine and Saudi Arabia Reach ‘Mutually Beneficial’ Defence Agreement
Ukraine to Share Battlefield Expertise with Saudi Arabia Under New Defence Agreement
Trump Takes Center Stage at Saudi Arabia’s FII Miami Amid Escalating Iran Conflict
Gulf States Explore Pipeline Routes to Bypass Strait of Hormuz Amid Rising Tensions
Iran Conflict Drives Saudi Arabia to Deepen Security Ties with Ukraine
Saudi Arabia Reviews Desert Ski Resort Plans with Cancellation of Key Building Contracts
Saudi Arabia Targets Business Hotel Shortfall with $1 Billion Development Push
Iran and Allied Forces Intensify Strikes on Energy Sites and Urban Areas Across Region
Ukraine and Saudi Arabia Formalise Defence Cooperation Agreement, Zelenskiy Announces
Saudi Arabia Reportedly Presses US to Intensify Operations Against Iran
Saudi Arabia Expands Maritime Network with Launch of Six New Shipping Services
Saudi Arabia Launches FII Summit Amid Heightened Focus on Global Stability and Investment Risks
Saudi Arabia’s HUMAIN Secures First US Customer in Expansion of AI Capabilities
Saudi Arabia Calls on US to Seize Strategic Opportunity to Reshape the Middle East
Saudi Arabia’s Strategic Investments Help Shape Silicon Valley’s Rise
Saudi Arabia Announces Passing of King Abdullah, Marking End of an Era
Saudi Arabia May Shift From Neutrality to Retaliation if Houthi Attacks Escalate, Experts Warn
UAE and Saudi Arabia Urge Decisive US Action on Iran as Regional Pressure Intensifies
Zelensky Visits Saudi Arabia After Offering Ukraine’s Drone Expertise
Saudi Arabia Pauses Ambitious Desert Ski Project Amid Strategic Reassessment
Trump Set for Palm Beach Return Following Saudi-Backed Summit in Miami
Saudi Arabia Accelerates Yanbu Oil Exports Toward Five Million Barrel Target
Report Highlights Saudi-US Security Discussions as Trump Administration Evaluates Iran Strategy
Saudi Arabia’s Humain Commits Three Billion Dollars to Elon Musk’s xAI in Strategic Technology Push
Saudi Arabia Signals Firm Shift in Iran Policy, Declares Coexistence No Longer Viable
Saudi Clubs Prepare Major Push to Sign Mohamed Salah Amid Growing Transfer Speculation
Saudi Arabia Rejects Claims It Seeks to Prolong Regional Conflict
Saudi Arabia Condemns Iranian Actions and Signals Firm Shift Toward Stronger Response
Saudi Arabia Reassesses Strategic Approach as Regional Tensions with Iran Intensify
Pakistan Reaffirms Strong Support for Saudi Arabia Following High-Level Visit
×