Dark Power

Compare
Parsing: enabled

View crypto

Description

Dark Power is a ransomware group first observed in January 2023, known for targeting small to mid-sized organizations across education, healthcare, manufacturing, and information technology sectors. The group uses a double-extortion model, encrypting files and threatening to leak exfiltrated data via a Tor-based site if ransom demands are not met. Written in the Nim programming language, Dark Power ransomware appends the .dark_power extension to encrypted files and drops a ransom note named README.txt, giving victims 72 hours to contact them. The note typically demands payment in cryptocurrency and offers to negotiate. Victims have been observed in North America, Asia, and Europe, with attacks often involving exploitation of vulnerable public-facing systems or stolen credentials.

External Analysis2
External Analysis
https://www.trellix.com/en-us/about/newsroom/stories/research/dark-power-ransomware.html
https://www.bleepingcomputer.com/news/security/dark-power-nim-based-ransomware-demands-10k-from-victims/
Urls1
Url
Status
Screen
Uptime 30d
Health
http://powerj7kmpzkdhjg4szvcxxgktgk36ezpjxvtosylrpey7svpmrjyuyd.onion/ Down Screen
Activity (interactive) 10
Activity charts
Posts10
Date Title Description Screen
onyx-pharma.dz
imtenan.com
agados.cz
evant.com.tr
arineta.com
rcc.gob.pe
goliplik.com.tr
mdclone.com
betastree.fr
northgatesd.net
Note