The FBI and CISA have issued a joint security alertfollowing the devastating attack on Colonial Pipeline by the DarkSide ransomware. The alert was published yesterday and provides details about the DarkSide group, which runs a Ransomware-as-a-Service (RaaS) network.
Learn more: Colonial Pipeline: Ransomware attack hits largest US fuel pipeline

DarkSide is responsible for the recent attack on Colonial Pipeline. Last week, the company that manages the largest fuel pipeline in the USsaid a cyberattack forced it to halt operations and shut down its IT systems to prevent the spread of malware.
The FBI is dealing with the case, since we are talking about an attack on the country's critical infrastructure.
See also: FBI/ACSC: Avaddon ransomware attacks are increasing at an alarming rate
“Cybercriminals use DarkSide to gain access to a victim’s network and encrypt and steal data,” the alert states. “These groups then threaten to expose the data if the victim does not pay the ransom. Groups exploiting DarkSide have recently targeted organizations in a variety of sectors, including: construction, legal and insurance firms, healthcare, and energy.”
DarkSide ransomware is delivered to RaaS customers. This “cybercriminal model” is quite popular, as it only requires a core team to develop malware, which can then be distributed to other criminals.
See also: Another American city victim of ransomware attack

In RaaS services, the creators provide the malware/ransomware to others and are paid a set amount or take a percentage of the ransom received by criminals who have used the ransomware. The developers continue to improve their malware “product.”.
It is alleged that DarkSide operators provide it to criminal clients who do not target healthcare, hospitals, or care providers. Darkside operators have distanced themselves from the attack on Colonial Pipeline (because it is a key fuel provider to the country) and have blamed their partners for the attack, without providing further details.
“Our goal is to make money, not to create problems for society,” the DarkSide gang said.

The FBI and CISA also recommend some practices to prevent or mitigate the threat of ransomware, especially for organizations involved with critical infrastructure.
Among other things, they advise organizations to be constantly vigilant and monitor their systems, while network segmentation and backups are essential.
Additional tips:
- Multi-factor authentication
- Spam filters to mitigate phishing, network traffic filters
- Training and awareness of employees on cybersecurity issues
- Regular system updates
- Implementation of security controls, risk assessment
- RDP restrictions
“CISA and the FBI do not encourage the payment of ransoms to criminals,” the organizations added. “Paying ransoms may encourage adversaries to target additional organizations, encourage other criminals to participate in ransomware distribution, and/or fund illegal activities. Paying the ransom does not guarantee the recovery of a victim’s files.”
Source: ZDNet
