Grupo de ransomware

Dark Project

Dark Project is a newly observed ransomware and data-extortion brand that publicly emerged through a Tor leak site on 2026-08-05. Eighteen organizations appeared in an initial same-day batch; Long-Lewis Automotive Group was subsequently observed as an additional claim, producing a 19-organization working set.

The operation maintains a principal onion portal, eight onion file servers, an OnionMail contact address and a Tox identity. Public descriptions emphasize internal files, personal data, medical information, engineering plans, financial records and operational documents.

The victim set is overwhelmingly North American and specifically U.S.-centric: 17 of 19 organizations are headquartered in the United States, one in Canada and one in Mexico. The U.S. share is approximately 89.5%.

Dark Project should currently be characterized as an emerging ransomware and data-extortion operation, not as a technically validated, distinct ransomware family. Only limited actor-originated material supports encryption, and no locker sample or reverse engineering was identified.

INFERENCE (confidence: high): The same-day publication batch is unlikely to represent same-day compromise activity. It more plausibly reflects a pre-launch backlog, delayed disclosure, affiliate-supplied cases or a coordinated leak-site debut.

INFERENCE (confidence: medium-high): The target pattern is data-value-driven rather than sector-exclusive, with a preference for small and mid-sized organizations holding sensitive business and personal records.

INFERENCE (confidence: medium): The eight file servers indicate prior preparation for segmented or distributed publication of large victim archives.

Creado por iQBlack CTI Team
Colaboradores 1
Última actualización 2026-08-19