> CLASSIFIED_DOSSIER :: THREAT_ACTOR_PROFILE
DARK ANGELS
/actor/dark-angels/ · 0 intel reports
Dark Angels is a sophisticated ransomware operation that emerged in 2022 and rapidly distinguished itself within the cybercriminal ecosystem through its focus on "big game hunting" , the deliberate targeting of large enterprises capable of paying multi-million dollar ransom demands, in contrast to the mass-deployment approach favoured by some ransomware affiliates.
The group made headlines in 2024 when security researchers revealed that Dark Angels had received a record-breaking $75 million ransom payment from a Fortune 50 pharmaceutical company , the largest single ransomware payment ever publicly disclosed. This payment significantly exceeded previous records and validated the group's patient, high-value targeting strategy.
Dark Angels is notable for its operational discretion: unlike many ransomware groups that seek public attention and post victim data on leak sites aggressively, Dark Angels operates quietly and has shown willingness to negotiate and delete data upon payment without public embarrassment of victims. This approach may reflect a calculated strategy to encourage future victim compliance by demonstrating reliability as counterparties in criminal negotiations.
The group's malware, based on the leaked Babuk ransomware source code adapted for both Windows and VMware ESXi environments, demonstrates their technical proficiency. Their targeting of healthcare, industrial, and technology sectors across North America and Europe reflects a careful assessment of victim payment capacity and operational impact sensitivity.
Tactical Telemetry and Extortion Framework: In confirmed intrusions, Dark Angels employs double-extortion tactics, combining high-speed asymmetric encryption with automated data exfiltration pipelines. Initial access is routinely obtained via compromised Remote Desktop Protocol (RDP) credentials, initial access broker (IAB) marketplaces, and spear-phishing campaigns delivering infostealer payloads. Organizations operating critical IT infrastructure are advised to enforce strict network segmentation, deploy hardware-backed multi-factor authentication across all external access points, and maintain immutable offline backups to mitigate operational disruption.
Threat Mitigation and Strategic Hardening: Network defense against campaigns linked to Dark Angels requires continuous threat surface management, dark web monitoring for stolen employee credentials, and automated telemetry correlation. Organizations should reference our Cyber Risk Checker and report critical indicators via Secure Drop.
> LINKED_INTEL_REPORTS (0)
[NULL] No intel reports found for this actor.