[ACCESS GRANTED] /// TATT-DB: ACTOR PROFILE LOADED ///

> DarkSide

[pwnbase.io V.2.1.0_FUI]

/// CORE METADATA
PRIMARY ROLE: Ransomware as a Service (RaaS) Operator
STATUS: ACTIVE / HIGH THREAT
MOTIVATION: Financial
TARGETS: US Oil/Gas Infrastructure, Finance, Manufacturing
USERNAMES: Darksupp (Dark Web Forum)
/// DATASET: MOST POPULAR BREACHES & SALES LOG (3 records)
[Colonial Pipeline] May 2021 | Data: Operational shutdown of the major US fuel pipeline.. Context: $4.4 million BTC ransom paid; forced shutdown of IT network..
[CompuCom (MSP)] Mar 2021 | Data: IT managed services provider compromise (Supply Chain).. Context: Cost over $20 million in restoration expenses..
[Brenntag] Apr 2021 | Data: Exfiltrated 200GB of data from the German chemical distributor.. Context: Ransom of $4.4 million paid..
/// TTP MAPPING: MITRE ATT&CK FRAMEWORK
Tactic MITRE ID Technique Description Defense Focus
[Credential Access] T1003 OS Credential Dumping: Used tools like Mimikatz, NTLM relay, and mined credentials from Chrome/Firefox profile folders. LSASS Protection, Browser Password Policy
[Defense Evasion] T1070.004 Indicator Removal: Used anti-forensics techniques including deleting log files and custom tools to avoid EDR. Off-host log collection, EDR Behavioral Monitoring
[Initial Access] T1078 Valid Accounts: Gained initial entry through compromised contractor accounts accessing Virtual Desktop Infrastructure (VDI). MFA on VDI, Strong Vendor Credential Management
[Command and Control] T1573.002 Encrypted Channel: Established C2 primarily with an RDP client running over port 443, routed through the **TOR network**. TOR Egress Monitoring, C2 Domain Blocking
/// WEAPONIZATION: KEY TOOLS & ARTIFACTS
DarkSide Encryptor [Ransomware (Custom)] Cobalt Strike [C2/Lateral Movement] advanced_ip_scanner.exe [Discovery/Scanning] Mimikatz [Credential Dumping]

[END OF FILE]