// THREAT ACTOR
DARKSIDE_
DormantDarkSide was a ransomware-as-a-service operation that briefly dominated headlines in 2021 after one of its affiliates carried out the Colonial Pipeline attack. Faced with US government attention, the operators announced a shutdown and rebranded — successor activity attributed to BlackMatter and ALPHV/BlackCat is widely traced back to the same operators.
For Ransomnews editorial coverage of DARKSIDE — incident write-ups, attribution notes, and additional context — see the Threat Groups archive or run a site search.
Leak site mirrors
3 mirrors tracked, 0 currently reachable. These are criminal-infrastructure URLs — links are deliberately not provided.
-
darksidc3iux462n6yunevoag52ntvwp6wulaz3zirkmh4cnz6hhj7id.onionsnapshot · 2021-09-08 00:04 -
dark24zz36xm4y2phwe7yvnkkkkhxionhfrwp67awpb3r3bdcneivoqd.onionsnapshot · 2024-12-09 20:35 -
darksidedxcftmqa.onionsnapshot · 2025-07-08 17:44