DarkSide Ransomware: $90M in Bitcoin Extorted from 47 Victims

The DarkSide ransomware group, which is thought to be behind the attacks on the Colonial pipeline, has made around $90 million in Bitcoin from 47 victims.
According to cyber security firm Elliptic's co-founder and chief scientist Tom Robinson, victims made just over $90 million in Bitcoin ransom payments to DarkSide, originating from 47 distinct wallets. According to DarkTracer, DarkSide ransomware has infected 99 organizations, which suggests that around 47% of victims paid a ransom, and the average payment was $1.9 million.
“To our knowledge, this analysis includes all payments made to DarkSide, however further transactions may yet be uncovered, and the figures here should be considered a low bound,” said Robinson.
Cyber criminal gangs such as DarkSide have established a ransomware-as-a-service business model where they develop the malware but allow other hackers to breach victims. DarkSide then splits the proceeds between themselves and their affiliates.
In DarkSide’s case, the developer reportedly takes 25% for ransoms less than $500,000, but this decreases to 10% for ransoms greater than $5 million.
Blockchain analysis makes money split clear, with the different shares going to separate Bitcoin wallets controlled by the affiliate and developer.
Robinson said the DarkSide developer has received Bitcoins worth $15.5 million (17%), with the remaining $74.7 million (83%) going to the various affiliates.
Further analysis allowed the firm to see where the cryptocurrency was being spent or exchanged. Most of the funds were sent to cryptoasset exchanges, where they can swap them for other cryptoassets, or fiat currency, said Robinson.
Robinson said that most cryptoasset exchanges comply with anti-money laundering (AML) regulations, verifying customers’ identity, and reporting suspicious activity, such as ransomware proceeds.
“However, some jurisdictions do not enforce these regulations, and it is to exchanges in these locations that much of the DarkSide ransomware proceeds are being sent,” said Robinson.
The DarkSide ransomware group, believed to be based in Eastern Europe or Russia, has recently disbanded after further investigations by US law enforcement. An email to DarkSide’s affiliates said that it was shutting up shop “due to the pressure of the US.”
However, many criminal gangs have been said they are disbanding only to show up again weeks or months later under a new name.
Blockchain
- Multiple IRAs: Can You Open More Than One? | [Financial Institution Name]
- Bitcoin's Energy Consumption: A Comparative Analysis
- Square Invests $170 Million in Bitcoin – A Sign of Corporate Confidence?
- Bitcoin's Surge: Will Elon Musk's Investment Yield a $200 Million Profit?
- FBI's $2.3M Bitcoin Seizure: Implications for the Crypto Market
- Crypto Utility Report: Majority of Top 100 Cryptocurrencies Lack Real-World Use
- Bitcoin's Energy Consumption: Surpassing a UK Household's Usage
- Bitcoin's Bullish Momentum: Why Now is Different Than April 2021
- Tether Surpasses Bitcoin & Ethereum with $2.3 Trillion Monthly Trading Volume
-
Medibloc Price Explodes 123% Amid Crypto Altcoin Rally; Dimon's Bitcoin Comments RecalledMedibloc prices surged 123% over the last 24 hours as traders continued to pile money into alternatives coins. Medibloc isnt a household name, but it was todays top performer in the space. While its...
-
Twitter Security Breach: 1,000+ Employees Had Access to Critical ToolsUPDATE: Over 1,000 Twitter employees and contractors are said to have had access to the same internal tools that are believed to have allowed cyber criminals to obtain control over 36 high-profile acc...
