The Darkside ransomware group announced their RaaS (Ransomware-as-a-Service) in August of 2020 via a “press release. DarkSide states that they only target companies that can pay the specified ransom giving the impression as they do not “want to kill businesses” in other words Darkside ransomware first conduct thorough study of organization they’re targeting to check whether the victims organization is able to fulfill their demand or not,
Threat actors have been targeting Government sector, education, health, non profit organizations, with ransom demands range from $200,000 to $2,000,000. These numbers can likely be more or less depending on the victim.
DarkSide will first steal your data and then encrypt your files and like other human-operated ransomware attacks, when the DarkSide operators breach a network, they will spread laterally throughout a network until they gain access to an administrator account and the Windows domain controller.While they spread laterally, the attackers will harvest unencrypted data from the victim’s servers and upload it to their own devices.
Furthermore, DarkSide will post the data leak site under their control and used as part of the extortion attempt in order to scare the victim of the into paying the ransom even if they can recover from backups.