Beautiful Virgin Islands

Tuesday, Jun 03, 2025

Firm tracked DarkSide gang ransomware payments and the massive sums paid

Firm tracked DarkSide gang ransomware payments and the massive sums paid

Blockchain analytics group tracked 75 BTC payment made by Colonial Pipeline after cyberattack

An analytics firm identified the bitcoin wallet used by the ransomware group behind the Colonial Pipeline attack and the massive payments received from victims.

The gang’s wallet received a 75 BTC (bitcoin) payment, or roughly $5 million, made by Colonial Pipeline on May 8 following the cyberattack on its operations, according to a report from blockchain analytics firm Elliptic.

The Colonial Pipeline shutdown led to widespread fuel shortages in the U.S. and has been described as the worst cyberattack on critical U.S. infrastructure to date. DarkSide, which the FBI confirmed as being behind the attacks, is believed to have originated in Eastern Europe, likely Russia. The group's ransomware was first spotted in August 2020.

Motorists use gas pumps at a refueling station on May 12, 2021 in Benson, North Carolina. Most stations in the area along I-95 were without fuel following the Colonial Pipeline hack. 


The firm also tracked a ransomware bitcoin payment made by Brenntag, a large chemical distribution company in Germany, totaling roughly $ 4.4 million.

The group's wallet has been active since March 4, 2021, and has received 57 payments from 21 different wallets, according to Elliptic.

In total, the DarkSide wallet received Bitcoin transactions since March totaling $17.5 million, Elliptic said. The firm said the majority of the payment was moved out the wallet on May 9.

A portion of the payments was sent to a small group of exchanges. One exchange was identified as Hydra, "the world’s largest darknet marketplace, servicing customers in Russia and neighboring countries," according to Elliptic.

Hydra offers "cash-out services" along with narcotics, hacking tools and fake IDs, the report said.

"These allow Bitcoin to be converted into gift vouchers, prepaid debit cards or cash Rubles. If you’re a Russian cybercriminal and you want to cash-out your crypto, then Hydra is an attractive option," Elliptic said.

Massive payments


DarkSide, which has since claimed it would cease operations, brought in a cool $90 million in just nine months from an estimated 47 victims, according to another report from Elliptic.

So far, 99 organizations have been infected with the DarkSide ransomware, "suggesting that approximately 47% of victims paid a ransom, and that the average payment was $1.9 million," Elliptic said, citing a tweet by DarkTracer.


Because of the large sums paid out by victims, ransomware has evolved into a big business that mirrors traditional business models.

DarkSide is a prime example of Ransomware as a Service (RaaS), Elliptic said, echoing longstanding legitimate models such as SaaS or Software as a Service.

"In this operating model, the malware is created by the ransomware developer, while the ransomware affiliate is responsible for infecting the target computer system and negotiating the ransom payment with the victim organization," Elliptic said.

"This new business model has revolutionized ransomware, opening it up to those who do not have the technical capability to create malware, but are willing and able to infiltrate a target organization," according to the analytics firm.

Newsletter

Related Articles

Beautiful Virgin Islands
0:00
0:00
Close
China Accuses US of Violating Trade Truce
Panama Port Owner Balances US-China Pressures
France Implements Nationwide Outdoor Smoking Ban to Protect Children
German Chancellor Merz Keeps Putin Guessing on Missile Strategy
Mandelson Criticizes UK's 'Fetish' for Abandoning EU Regulations
British Fishing Boat Owner Fined €30,000 by French Authorities
Dutch government falls as far-right leader Wilders quits coalition
Harvard Urges US to Unfreeze Funds for Public Health Research
Businessman Mauled by Lion at Luxury Namibian Lodge
Researchers Consider New Destinations Beyond the U.S.
53-Year-Old Doctor Claims Biological Age of 23
Trump Struggles to Secure Trade Deals With China and Europe
Russia to Return 6,000 Corpses Under Ukraine Prisoner Swap Deal
Microsoft Lays Off Hundreds More Amid Restructuring
Harvey Weinstein’s Publicist Embraces Notoriety
Macron and Meloni Seek Unity Despite Tensions
Trump Administration Accused of Obstructing Deportation Cases
Newark Mayor Sues Over Arrest at Immigration Facility
Center-Left Candidate Projected to Win South Korean Presidency
Trump’s Tariffs Predicted to Stall Global Economic Growth
South Korea’s President-Elect Expected to Take Softer Line on Trump and North Korea
Trump’s China Strategy Remains a Geopolitical Puzzle
Ukraine Executes Long-Range Drone Strikes on Russian Airbases
Conservative Karol Nawrocki wins Poland’s presidential election
Study Identifies Potential Radicalization Risk Among Over One Million Muslims in Germany
Good news: Annalena Baerbock Elected President of the UN General Assembly
Apple Appeals EU Law Over User Data Sharing Requirements
South Africa: "First Black Bank" Collapses after Being Looted by Owners
Poland will now withdraw from the EU migration pact after pro-Trump nationalist wins Election
"That's Disgusting, Don’t Say It Again": The Trump Joke That Made the President Boil
Trump Cancels NASA Nominee Over Democratic Donations
Paris Saint-Germain's Greatest Triumph Is Football’s Lowest Point
OnlyFans for Sale: From Lockdown Lifeline to Eight-Billion-Dollar Empire
Mayor’s Security Officer Implicated | Shocking New Details Emerge in NYC Kidnapping Case
Hegseth Warns of Potential Chinese Military Action Against Taiwan
OPEC+ Agrees to Increase Oil Output for Third Consecutive Month
Jamie Dimon Warns U.S. Bond Market Faces Pressure from Rising Debt
Turkey Detains Istanbul Officials Amid Anti-Corruption Crackdown
Taylor Swift Gains Ownership of Her First Six Albums
Bangkok Ranked World's Top City for Remote Work in 2025
Satirical Sketch Sparks Political Spouse Feud in South Korea
Indonesia Quarry Collapse Leaves Multiple Dead and Missing
South Korean Election Video Pulled Amid Misogyny Outcry
Asian Economies Shift Away from US Dollar Amid Trade Tensions
Netflix Investigates Allegations of On-Set Mistreatment in K-Drama Production
US Defence Chief Reaffirms Strong Ties with Singapore Amid Regional Tensions
Vietnam Faces Strategic Dilemma Over China's Mekong River Projects
Malaysia's First AI Preacher Sparks Debate on Islamic Principles
White House Press Secretary Criticizes Harvard Funding, Advocates for Vocational Training
France to Implement Nationwide Smoking Ban in Outdoor Spaces Frequented by Children
×