darkbit
1 incidentes
1 paises
1 sectores
ransomware RU Ultimo: 2026-06-25
DarkBit is a politically-motivated ransomware group that first emerged in early 2023, notably around February 11, with its initial observed activity targeting an Israeli technical university. While some reports attribute the group to a Russian-speaking cybercrime gang, Israeli cybersecurity officials have linked DarkBit to Iranian government-sponsored threat actors like MuddyWater, an attribution supported by the strong anti-Israel sentiments expressed in their ransom notes and social media campaigns. The group's primary motivation combines political hacktivism, branding themselves as "Hackers for Good" against racism, fascism, and apartheid, with the financial gain typical of ransomware operations. DarkBit distinguishes itself through its explicit ideological messaging, its use of social media platforms for influence operations and data leaks, and its development of a custom Golang-based ransomware that is a modified variant of LockBit. The group operates using a Ransomware-as-a-Servi
RansomLook pivots
Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.
Abrir perfil →
Paises objetivo (SOCRadar)
China
IsraelIran, Islamic Republic of
United States
Sectores atacados
Government (1)
Sectores objetivo (SOCRadar)
Energy & Utilities ManufacturingInformation ServicesFinanceProfessional&Technical ServicesEnterprises & HoldingEducational ServicesHealthCare & Social AssistanceOtherPublic Administration
URLs nuevas detectadas en IntelTracker