DarkSide, the gang behind Colonial attack, claims it lost control of web servers and funds, as researchers wonder whether a US takedown or exit scam is to blame
the one responsible for attacking Colonial Pipeline — closes after its servers were seized and cryptocurrency holdings mysteriously disappeared. Closure comes as crime forums start banning ransomware threads https://krebsonsecurity.com/ ... Greg Otto / @gregotto : After that, REvil AND Avaddon announced new “rules,” barring affiliates from targeting gov, healthcare, edu and charity organizations regardless of their country of operation. Affliates also now need pre-approval https://www.intel471.com/... Greg Otto / @gregotto : Then, the operator of REvil announced they would stop promoting their malware on the above forum. Operator also said REvil would continue operating on another well-known forum, but expected to be banned there too. https://www.intel471.com/... Greg Otto / @gregotto : After dumping the DC police data, Babuk claimed it handed over the ransomware's source code to “another team,” which would continue to develop it under a new brand. The group pledged to stay in business, urged others to go private https://www.intel471.com/... Greg Otto / @gregotto : DarkSide releases a msg saying they are done, adding that their infrastructure was seized — Victim blog, CDN, ransom collection site — and their crypto wallets were emptied. Also sent affiliates decryption tools to unlock any ongoing ransom incidents. https://www.intel471.com/... Greg Otto / @gregotto : NEW BLOG: There has been a big upheaval among ransomware operators in the past 24 hours. DarkSide has announced its shutting down operations, REvil and Avaddon announcced new “rules” and a big cybercrime forum has BANNED anything to do with ransomware. https://www.intel471.com/... Ken Dilanian / @kendilaniannbc : If this was the US government, it raises the question of why it took so long and why it's not done more often. https://twitter.com/... Greg Otto / @gregotto : A CAVEAT: All of these are claims coming from the criminals. They are as trustworthy as the guy in the picture below. Actions will always speak louder than words. Ransomware isn't going anywhere and @Intel471Inc will continue to watch https://www.intel471.com/... https://twitter.com/... Helen Kennedy / @helenkennedy : Looks like the guys who took down the Colonial pipeline have been taken down. https://twitter.com/... Greg Otto / @gregotto : Shortly thereafter, the admin for a popular Russian-lang crime forum announced a ban of all ransomware-related activity. The forum now prohibits ransomware ads, sales, negotiation services and similar offers. Any current listings will be deleted. https://www.intel471.com/... Zack Whittaker / @zackwhittaker : “Intel 471 observed numerous ransomware operators & cybercrime forums either claim their infrastructure has been taken offline, amending their rules or they are abandoning ransomware altogether due to the large amount of negative attention directed their way over the past week.” https://twitter.com/... Kim Zetter / @kimzetter : Hmm: “Intel 471 has observed numerous ransomware operators & cybercrime forums either claim their infrastructure has been taken offline, amending their rules, or they are abandoning ransomware...due to the large amount of negative attention...the past wk” https://www.intel471.com/...
Context & Ripple Effects
DarkSide’s attack forced Colonial Pipeline to halt operations before the company restarted after a five-day shutdown, turning a ransomware operation into a high-visibility infrastructure incident. In the immediate aftermath, DarkSide had publicly proposed more selective target moderation, while the reported loss of its servers and funds now ends its operations altogether.
The closure coincides with a Russian-language crime forum’s ban on ransomware activity and new affiliate restrictions from REvil and Avaddon, indicating that the Colonial episode is reshaping the operating environment around ransomware-as-a-service.
First-order effects
- DarkSide’s affiliates lose access to the group’s operating infrastructure and ransom-collection channel; DarkSide says it sent them decryption tools for active incidents before shutting down.
- Victims tied to ongoing DarkSide attacks face a disrupted negotiation and payment process as the group’s victim blog, CDN and collection site are no longer under its control.
Second-order effects
- REvil and Avaddon’s new prohibitions on government, healthcare, education and charity targets, plus pre-approval requirements, make affiliate recruitment and target selection more controlled across rival ransomware operations.
- The crime-forum ban and DarkSide’s disappearance push ransomware operators away from prominent public marketplaces, raising the value of private infrastructure and trusted affiliate networks.
Third-order effects
- If major ransomware brands can lose both infrastructure and cryptocurrency access after a high-profile attack, ransomware-as-a-service becomes less durable as a public-facing franchise and more dependent on compartmentalized operators.
- The episode points toward a ransomware market in which forum operators and gang administrators impose their own target controls to reduce attention, even as successor groups such as Babuk’s planned rebrand preserve the underlying model.
The trend: High-profile attacks are forcing ransomware-as-a-service groups to trade public scale and loose affiliate access for more controlled, less visible operations.