Beautiful Virgin Islands

Tuesday, Mar 17, 2026

Firm tracked DarkSide gang ransomware payments and the massive sums paid

Firm tracked DarkSide gang ransomware payments and the massive sums paid

Blockchain analytics group tracked 75 BTC payment made by Colonial Pipeline after cyberattack

An analytics firm identified the bitcoin wallet used by the ransomware group behind the Colonial Pipeline attack and the massive payments received from victims.

The gang’s wallet received a 75 BTC (bitcoin) payment, or roughly $5 million, made by Colonial Pipeline on May 8 following the cyberattack on its operations, according to a report from blockchain analytics firm Elliptic.

The Colonial Pipeline shutdown led to widespread fuel shortages in the U.S. and has been described as the worst cyberattack on critical U.S. infrastructure to date. DarkSide, which the FBI confirmed as being behind the attacks, is believed to have originated in Eastern Europe, likely Russia. The group's ransomware was first spotted in August 2020.

Motorists use gas pumps at a refueling station on May 12, 2021 in Benson, North Carolina. Most stations in the area along I-95 were without fuel following the Colonial Pipeline hack. 


The firm also tracked a ransomware bitcoin payment made by Brenntag, a large chemical distribution company in Germany, totaling roughly $ 4.4 million.

The group's wallet has been active since March 4, 2021, and has received 57 payments from 21 different wallets, according to Elliptic.

In total, the DarkSide wallet received Bitcoin transactions since March totaling $17.5 million, Elliptic said. The firm said the majority of the payment was moved out the wallet on May 9.

A portion of the payments was sent to a small group of exchanges. One exchange was identified as Hydra, "the world’s largest darknet marketplace, servicing customers in Russia and neighboring countries," according to Elliptic.

Hydra offers "cash-out services" along with narcotics, hacking tools and fake IDs, the report said.

"These allow Bitcoin to be converted into gift vouchers, prepaid debit cards or cash Rubles. If you’re a Russian cybercriminal and you want to cash-out your crypto, then Hydra is an attractive option," Elliptic said.

Massive payments


DarkSide, which has since claimed it would cease operations, brought in a cool $90 million in just nine months from an estimated 47 victims, according to another report from Elliptic.

So far, 99 organizations have been infected with the DarkSide ransomware, "suggesting that approximately 47% of victims paid a ransom, and that the average payment was $1.9 million," Elliptic said, citing a tweet by DarkTracer.


Because of the large sums paid out by victims, ransomware has evolved into a big business that mirrors traditional business models.

DarkSide is a prime example of Ransomware as a Service (RaaS), Elliptic said, echoing longstanding legitimate models such as SaaS or Software as a Service.

"In this operating model, the malware is created by the ransomware developer, while the ransomware affiliate is responsible for infecting the target computer system and negotiating the ransom payment with the victim organization," Elliptic said.

"This new business model has revolutionized ransomware, opening it up to those who do not have the technical capability to create malware, but are willing and able to infiltrate a target organization," according to the analytics firm.

Newsletter

Related Articles

Beautiful Virgin Islands
0:00
0:00
Close
Western Allies Urge Restraint as Israel Weighs Expanded Ground Operation in Lebanon
Trump Warns NATO Faces ‘Very Bad’ Future Without Stronger Allied Support in Iran Conflict
UK Minister Says Britain Not Bound to Support Every Demand From U.S. President
Starmer Tells Trump Britain Will Not Be Drawn Into Wider Iran War
Starmer Tells Trump Britain Will Not Be Drawn Into Wider Iran War
UK Set to Introduce Steel Tariffs of Up to 50 Percent in New Industrial Strategy
European Governments Decline Trump’s Call to Send Warships to Reopen Strait of Hormuz
Fears Over Iran Conflict Weigh on UK Consumer Confidence
Starmer Says UK Working With Allies on Hormuz Shipping Plan After Trump Raises Pressure
Iran War and Energy Shock Shake Britain’s Economy and Political Debate
Deadly Meningitis Outbreak at UK University Leaves Two Dead and Several Seriously Ill
Deadly Meningitis Outbreak at UK University Leaves Two Dead and Several Seriously Ill
King Charles and Queen Camilla Share Personal Tributes to Their Mothers on UK Mother’s Day
Prince William Honors Princess Diana with Mother’s Day Tribute
UK Economy Stalls in January as Households Cut Back on Eating Out
AI-Generated Singer Becomes Viral Voice for Iranians With New Anthem
London Private Club Founder Plans Exclusive Palm Beach Venue Near Trump’s Mar-a-Lago
Ed Davey Urges Britain to Build Fully Independent Nuclear Missile Capability
What the UK Covid Inquiry Is and How It Investigates Britain’s Pandemic Response
What the UK Covid Inquiry Is and How It Investigates Britain’s Pandemic Response
US Treasury Links British Polo Patrons to Alleged Venezuelan Oil Proceeds Laundering Scheme
Hundreds Gather in London Despite Ban on Annual Pro-Palestinian March
Two Dead and Multiple Students Seriously Ill After Invasive Meningitis Outbreak at UK University
UK Considers Deploying Ships and Mine-Hunting Drones to Reopen Strait of Hormuz
Starmer and Trump Discuss Urgent Need to Reopen Strait of Hormuz Amid Escalating Iran Conflict
Prince Harry and Meghan Markle’s Planned Australia Visit Draws Mixed Reaction From Local Communities
Trump Calls on France and UK to Help Safeguard Strait of Hormuz Shipping Route
Boris Johnson Labels Bitcoin a ‘Ponzi Scheme’, Sparking Debate in Crypto World
UK Considers Targeted Aid for Vulnerable Households as Energy Costs Rise
Stellantis Urges Immediate Review of UK Electric Vehicle Sales Targets
Home Office Reverses Course to Allow Some Dual Nationals to Enter UK Using EU Passports
Reform UK Proposes Replacing Top Civil Servants With Officials Aligned to Government Agenda
Netflix Adds Critically Acclaimed ‘Best Film of 2025’ With Perfect Rotten Tomatoes Score
‘The Sums Don’t Add Up’: UK Farmers Hit by Soaring Costs as Iran War Disrupts Global Supplies
Confidential UK Biobank Health Records Found Online After Researchers Accidentally Expose Data
Trump Urges Britain and Allies to Deploy Warships to Safeguard Strait of Hormuz
Trump Urges Britain and Allies to Deploy Warships to Safeguard Strait of Hormuz
Middle East War Highlights Strategic Importance of Strong UK–Ireland Cooperation
Weak Growth Signals UK Economy Was Faltering Even Before Middle East Energy Shock
Marks & Spencer Tops UK Fashion Retail Rankings as Most Considered Brand
United States Launches Trade Investigation Into Allies Over Forced Labour Practices
United States Launches Trade Investigation Into Allies Over Forced Labour Practices
Russia Accuses Britain Over Storm Shadow Strike as London Reaffirms Ukraine’s Right to Self-Defence
Russia Accuses Britain Over Storm Shadow Strike as London Reaffirms Ukraine’s Right to Self-Defence
Royal Navy to Acquire Twenty Uncrewed Surface Vessels for Autonomous Warfare Testing
Russia Summons British and French Envoys After Ukrainian Storm Shadow Strike on Strategic Facility
Starmer Confirms Britain Will Maintain Sanctions on Russia Despite U.S. Policy Shift
UK Moves to Refine AI Definition in Investment Security Reform
UK Economy Stalls in January as Growth Unexpectedly Falls to Zero
Asian Energy Security Tested as Strait of Hormuz Disruption Threatens Oil Supplies
×