216.73.217.69

Dark Angels Exposed

· Published 08/10/2024 22:49 · Modified 09/10/2024 08:05

Export JSON

Essential information

Published
08/10/2024 22:49
Modified
09/10/2024 08:05
Tags
2024-10-08 CVE-2023-22069 babuk data exfiltration raas ragnarlocker ransomware
Related entities
1 intrusion sets (apt), 20 techniques (mitre), 5 malware, 5 others

Description

The Dark Angels group, active since April 2022, operates with sophisticated strategies targeting large companies for substantial ransom demands. They focus on stealthy attacks, avoiding outsourcing to third-party brokers. The group uses various payloads, including and Read the Manual (RTM) Locker for Windows, and a variant for Linux/ESXi systems. Dark Angels emphasizes data theft over file encryption, often demanding payment to prevent data leaks. Their tactics include network infiltration, lateral movement, and selective deployment based on potential business disruption. The group has claimed a record $75 million ransom payment and operates a data leak site called Dunghill Leak.

External references