Ransomware Intelligence

Ransomware needs a way in. Stolen credentials are the cheapest one.

Check Your Exposure

dark project Ransomware Group

Ransomware group profile

6Victims
RussiaSource country
65Impact score

Description

Dark Project is a financially motivated double-extortion ransomware and data-extortion operation that emerged in August 2026. The group uses a dedicated Tor leak portal to publish stolen sensitive data, coercing organizations into paying ransoms to avoid exposure of corporate files and personal records. Their opportunistic targeting spans multiple industries and geographic regions, aiming for high volume data breaches.

Key insights

  • Initial access is achieved through phishing, exploiting remote desktop services, or compromised credentials from infostealer logs.
  • Dark Project exfiltrates vast amounts of sensitive data, from 40GB to over 2TB, including personal and financial records.
  • They employ a double-extortion tactic using a Tor-based leak site to publish stolen data if ransoms are not paid.
  • The group targets various sectors opportunistically, including healthcare, manufacturing, and professional services.
  • Publication of victim identifiers and dataset volumes occurs on their dedicated leak portal.
  • Financial gain is the primary motivation for their criminal activities.

Threat Level & Status Breakdown

For dark project · Based on incidents in selected period

1.9threat level
Aggressiveness1.5/ 10
Lethality0.8/ 10
Criticality3.6/ 10

Status Breakdown

Data Leaked16.7%1
Claimed83.3%5
First seenAug 2026
Last seenAug 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedSep 5, 2026

Recent activity

Monthly attack count for dark project in the selected period

6Total attacks
6peak in Aug
6avg / month
Aug02468

No intelligence data for this group.

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for dark project

Collection

T1560

Archive Collected Data

Defense Evasion

T1562

Impair Defenses

Execution

T1059

Command and Scripting Interpreter

T1105

Ingress Tool Transfer

Impact

T1486

Data Encrypted for Impact

T1490

Inhibit System Recovery

Lateral Movement

T1021

Remote Services

Other

T1048

T1048

Persistence

T1078

Valid Accounts

T1547

Boot or Logon Autostart Execution

Victims(6)

United StatesManufacturingpumpengineering.net
Claimed
12 days ago
United StatesHealthcaredentistinnewbritain.com
Claimed
12 days ago
United StatesProfessional Servicesjonesandlittle.com
Claimed
12 days ago
United StatesHospitalitylibertygrp.com
Data Leaked
12 days ago
United StatesHospitalityfurnishedquarters.com
Claimed
12 days ago
United StatesManufacturingdaengineering.com
Claimed
12 days ago

Affected countries(7)

Countries where this group has been reported to target or leak victims.