The Darkside ransomware gang has donated $10,000 of the ransom it has collected from its victims to Children International and The Water Project.

A ransomware gang has donated a portion of the ransom it has collected to charities.
The current recipients of the money are Children International, a non-profit organization funding children living in extreme poverty, and The Water Project, a non-profit organization aimed at providing access to clean water across Africa.
Each organization appears to have received 0.88 bitcoins last week.
The sender was a ransomware group called Darkside. The Darkside group, active since August 2020, is a classic “big game hunter,” meaning it specifically targets large corporate networks, encrypts data , and demands huge ransoms in the millions of dollars.
If victims do not pay, the Darkside group leaks their data online, on a portal they have on the dark web.
“As we said in the first press release – we only target large profitable companies,” the Darkside group wrote on a dark web portal page, published on Monday.
"We believe it is only fair that some of the money the victims have paid should be donated to charity .No matter how bad you think our work is, we are happy to know that we helped change someone's life," the group also added.
This “press release,” as the group calls it, comes after a similar one posted online in August, where the group promised not to encrypt files belonging to hospitals, schools, universities, non-profits, and government sectors.
Whether they kept their promise, of course, we don't know. Other ransomware gangs had also promised not to attack the healthcare sector at the start of the COVID-19, but ultimately failed to keep their word.
Furthermore, the Darkside group is not the first gang to donate money to charities and non-profit organizations.
In 2016, a hacking group called Phineas Fisher claimed to have hacked a bank and given the money to the autonomous Syrian province of Rojava.
In 2018, the GandCrab gang released free decryption for victims located in war-torn Syria.
The GandCrab gang also added an exception to code saying it would not encrypt the files of victims located in that country. Ironically, this exception for Syrian victims is what helped security researchers connect the group to the REvil ransomware when the GandCrab group went into hiatus and tried to start a new operation under a new name (REvil or Sodinokibi).
