Arab Press

بالشعب و للشعب
Friday, Mar 27, 2026

Infamous DarkSide ransomware reborn as new cyber threat: reports

Infamous DarkSide ransomware reborn as new cyber threat: reports

BlackMatter says it has the 'best features' of Colonial Pipeline hackers DarkSide, plus other kinds of ransomware

A new cyber gang is in town – and tapping into the best features of ransomware used in the Colonial Pipeline attack.

That new gang, BlackMatter, is upfront about its origins, stating that it has "incorporated" the "best features" of DarkSide and two other kinds of ransomware, REvil and Lockbit, according to a statement from the BlackMatter group as noted by cybersecurity company Recorded Future.

DarkSide was identified by the U.S. government as the ransomware responsible for the Colonial Pipeline attack, which resulted in the shutdown of a major pipeline supplying fuel to the U.S. East Coast.

A man leaves a Murrphy Oil gas station as pumps are seen out of gas, Tuesday, May 11, 2021, in Kennesaw, Ga. after Colonial Pipeline halted operations because of a cyberattack.


After the attack, DarkSide posted a statement saying it was ending operations.

Enter BlackMatter, which is now active on cybercrime forums.

"They’re not advertising their ransomware, however; they are recruiting affiliates…who have access to hacked enterprise networks," according to Malwarebytes. The BlackMatter ads state that it's seeking hacked access to corporate networks in Australia, Canada, the UK and the U.S.

Other requirements for corporations they target include revenue of at least $100 million and 500-15,000 hosts in the network, Recorded Future said.

Like other successful ransomware operations, BlackMatter is run as a business, dubbed Ransomware-as-a-service or RaaS, a knockoff of legitimate business models such as SaaS or software-as-a-service.

Cybersecurity news site Bleeping Computer reported attacks are happening already.

On their own site, BlackMatter says it won’t target certain industries including hospitals, critical infrastructure, the defense industry and the government sector, according to Malwarebytes.

That’s similar to past statements from DarkSide.

"Our goal is to make money, and not creating problems for society. From today we introduce moderation and check each company that our partners want to encrypt to avoid social consequences in the future," the DarkSide group said back in May.

But there may be more practical reasons for this. "Almost as if to say that they are keenly aware of the danger that comes from pulling off internationally-recognized attacks," Malwarebytes said.

In June, the Department of Justice said that it had seized Bitcoin valued at approximately $2.3 million from the DarkSide gang. Those funds represented a ransom payment for the Colonial Pipeline ransomware attack.

Newsletter

Related Articles

Arab Press
0:00
0:00
Close
Saudi Arabia Expands Maritime Network with Launch of Six New Shipping Services
Saudi Arabia Launches FII Summit Amid Heightened Focus on Global Stability and Investment Risks
Saudi Arabia’s HUMAIN Secures First US Customer in Expansion of AI Capabilities
Saudi Arabia Calls on US to Seize Strategic Opportunity to Reshape the Middle East
Saudi Arabia’s Strategic Investments Help Shape Silicon Valley’s Rise
Saudi Arabia Announces Passing of King Abdullah, Marking End of an Era
Saudi Arabia May Shift From Neutrality to Retaliation if Houthi Attacks Escalate, Experts Warn
UAE and Saudi Arabia Urge Decisive US Action on Iran as Regional Pressure Intensifies
Zelensky Visits Saudi Arabia After Offering Ukraine’s Drone Expertise
Saudi Arabia Pauses Ambitious Desert Ski Project Amid Strategic Reassessment
Trump Set for Palm Beach Return Following Saudi-Backed Summit in Miami
Saudi Arabia Accelerates Yanbu Oil Exports Toward Five Million Barrel Target
Report Highlights Saudi-US Security Discussions as Trump Administration Evaluates Iran Strategy
Saudi Arabia’s Humain Commits Three Billion Dollars to Elon Musk’s xAI in Strategic Technology Push
Saudi Arabia Signals Firm Shift in Iran Policy, Declares Coexistence No Longer Viable
Saudi Clubs Prepare Major Push to Sign Mohamed Salah Amid Growing Transfer Speculation
Saudi Arabia Rejects Claims It Seeks to Prolong Regional Conflict
Saudi Arabia Condemns Iranian Actions and Signals Firm Shift Toward Stronger Response
Saudi Arabia Reassesses Strategic Approach as Regional Tensions with Iran Intensify
Pakistan Reaffirms Strong Support for Saudi Arabia Following High-Level Visit
Saudi Arabia Expands Regional Trade Links by Opening New Land and Sea Routes to UAE
World Economic Forum Delays Saudi Conference as Regional Conflict Disrupts Global Agenda
Saudi Arabia and UAE Signal Potential Entry into Iran Conflict if Critical Infrastructure Is Targeted
Global Firms Accelerate Expansion into Saudi Arabia as Economic Reforms Gain Momentum
Global Labour Pressure Mounts as ILO Faces Calls to Reject Saudi Bid to Dismiss Migrant Worker Complaint
Gulf Powers Move Closer to Entering Iran Conflict as Regional Pressure Intensifies
Saudi Arabia Breaks Ranks with Regional Allies Over Response to Iran Escalation
Saudi Arabia Moves Closer to Direct Role as Iran Conflict Intensifies
World Economic Forum Postpones Jeddah Meeting Amid Escalating Regional Tensions
Trump to Deliver Keynote Address at Saudi-Backed Investment Summit in Miami Beach
Saudi Arabia and Kuwait Press Ahead With Energy Agreements Despite Regional Conflict
Can Saudi Arabia’s Yanbu Port Replace Hormuz? Capacity Limits Test Critical Oil Lifeline
Saudi Arabia Detects Ballistic Missiles as Regional Tensions Escalate in Gulf
Saudi Aramco Reduces Oil Shipments to Asia for Second Consecutive Month
Saudi Aramco Reduces Oil Shipments to Asia for Second Consecutive Month
Saudi Arabia and UAE Push Ahead With Major Deals Despite Iran-Related Uncertainty
Formula One Cancels Bahrain and Saudi Arabia Grands Prix Amid Escalating Regional Tensions
Pakistan Signals Strategic Realignment Toward Saudi Arabia Amid Regional Tensions
Saudi Arabia Cuts Oil Shipments to Asia as Regional Conflict Disrupts Key Export Routes
Saudi Arabia Moves to Contain Regional Escalation as Houthis Signal Readiness to Join Conflict
Saudi Arabia Signals Independent Nuclear Strategy Unaffected by Iran Tensions
Saudi Arabia Signals Independent Nuclear Strategy Unaffected by Iran Tensions
Egypt Reaffirms Strong Support for Saudi Arabia as Sisi Condemns Iran’s Gulf Attacks
Saudi Stocks Close Higher as Tadawul Index Gains 0.55% on Broad Sector Strength
Iran Fires Ballistic Missiles Toward Riyadh as Gulf Conflict Intensifies
Barcelona Midfielder Marc Casadó Attracts €40 Million Interest from Saudi Clubs
Strait of Hormuz Tensions Rise as Saudi Arabia Opens Key Air Base to US Forces
Saudi Arabia Confronts Strategic Turning Point as Iran Conflict Redefines Regional Alliances
Saudi Arabia Intercepts Missile as Two Others Land in Remote Area Without Casualties
Saudi Expulsion of Iranian Military Attaché Raises Doubts Over Fragile Riyadh–Tehran Rapprochement
×