Facebook
Twitter
LinkedIn
According to the data, the first appearance of the Darkside Ransomware happened around August 2020. Since then, the group behind the Darkside attacks has been targeting companies in all industries around the world.
The vision of Ransomware as a Service (RaaS) has become increasingly democratised among cybercriminals. Making any holder of the malware, see themselves empowered to carry out an attack against a company. The only demand from the group that sold the malware is to receive a percentage of each attack.
Admittedly, many hacker groups carry out mass attacks on random companies with the hope that one of them will agree to pay the ransom. However, the Darkside group’s history of attacking companies has highlighted a very thorough company-study strategy.
The complexity of the attacks and the targeting of large companies has shown an advanced understanding of the victim’s security structure and systems.
Besides being organised in their attacks, the Darkside group practice the notorious double extortion. Once the attack has succeeded, they ask for a second ransom payment for the victim, threatening to make the stolen information public.
In other words, in exchange for their data, the company will have to pay a first ransom to get their data back and a second to keep the cybercriminals from taking sensitive information to the general public. Which in turn can have numerous consequences, such as a fine for not complying with the General Data Protection Regulation (GDPR).
The Darkside group remains careful not to launch ransomware into the environment before certifying that the area has been mapped, valuable data has been extracted, control of privileged accounts has been assumed and all backup systems have been discovered. Only then do they begin the encryption.
As much as the group behind the Darkside Ransomware has been updating their malware with its version 2.0 in March 2021, their attack methodology basically remains unchanged. They stake their conquests on the following steps:
Despite the prowess and level of complexity that Darkside ransomware possesses, Digital Recovery has been over the past few years, recovering data and saving companies from ransomware attack. We can rely on experts in encrypted data recovery. Our tools allow us to recover data on virtually any storage device, such as Servers, Databases, Virtual Machines, RAID systems, among others.
All these solutions have been developed in accordance with the General Data Protection Regulation (GDPR). Due to the sensitivity of the data that a company may have, we also have a confidentiality agreement (NDA) for double security of your data.
Digital Recovery can now work remotely and, if the situation requires it, we offer emergency recovery. Our employees are available around the clock for any eventuality.
Regardless of the level of attack that your company has suffered, Digital Recovery may have the solution at hand. Contact our team and get your data recovered now.
Learn more about data recovery and technology innovations.
Let`s Talk?