Ransomware Intelligence

Ransomware needs a way in. Stolen credentials are the cheapest one.

Check Your Exposure

dark project Ransomware Group

Ransomware group profile

17Victims
RussiaSource country
68Impact score

Description

Dark Project is a financially motivated double-extortion ransomware and data-extortion operation that emerged in August 2026. The group uses a dedicated Tor leak portal to publish stolen sensitive data, coercing organizations into paying ransoms to avoid exposure of corporate files and personal records. Their opportunistic targeting spans multiple industries and geographic regions, aiming for high volume data breaches.

Key insights

  • •Initial access is achieved through phishing, exploiting remote desktop services, or compromised credentials from infostealer logs.
  • •Dark Project exfiltrates vast amounts of sensitive data, from 40GB to over 2TB, including personal and financial records.
  • •They employ a double-extortion tactic using a Tor-based leak site to publish stolen data if ransoms are not paid.
  • •The group targets various sectors opportunistically, including healthcare, manufacturing, and professional services.
  • •Publication of victim identifiers and dataset volumes occurs on their dedicated leak portal.
  • •Financial gain is the primary motivation for their criminal activities.

Threat Level & Status Breakdown

For dark project · Based on incidents in selected period

3.2threat level
Aggressiveness6.5/ 10
Lethality0.4/ 10
Criticality2.7/ 10

Status Breakdown

Data Leaked5.9%1
Claimed94.1%16
First seenAug 2026
Last seenSep 2026
Avg ransom—
Payment rate—
Statusactive
Sophistication0
Last updatedSep 27, 2026

Recent activity

Monthly attack count for dark project in the selected period

17Total attacks
11peak in Sep
8.5avg / month
↑ 5 vs first month
AugSep036912

No intelligence data for this group.

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for dark project

Collection

T1560

Archive Collected Data

Defense Evasion

T1562

Impair Defenses

Execution

T1059

Command and Scripting Interpreter

T1105

Ingress Tool Transfer

Impact

T1486

Data Encrypted for Impact

T1490

Inhibit System Recovery

Lateral Movement

T1021

Remote Services

Other

T1048

T1048

Persistence

T1078

Valid Accounts

T1547

Boot or Logon Autostart Execution

Victims(14)

United StatesHospitalityfurnishedquarters.com
Claimed
about 1 month ago
United StatesHealthcare
Claimed
2 days ago
United StatesManufacturingpumpengineering.net
Claimed
about 1 month ago
United StatesProfessional Servicesjonesandlittle.com
Claimed
about 1 month ago
United StatesManufacturing
Claimed
2 days ago
United StatesHospitality
Claimed
2 days ago
TurkeyManufacturingcumar.com
Claimed
13 days ago
United StatesManufacturingspecchem.com
Claimed
19 days ago
SingaporeProfessional Servicesmeiarchitects.com
Claimed
20 days ago
United StatesManufacturingmastermfg.com
Claimed
20 days ago
BrazilManufacturingalurwalls.com
Claimed
20 days ago
United StatesHealthcaredentistinnewbritain.com
Claimed
about 1 month ago
United StatesHospitalitylibertygrp.com
Data Leaked
about 1 month ago
United StatesManufacturingdaengineering.com
Claimed
about 1 month ago

Affected countries(8)

Countries where this group has been reported to target or leak victims.