◇ SIGN IN
← all actors
ransomware

DarkVault

unknownmedium confidence
Ransomware
Dark Vault
Attribution
Financially motivated (unattributed)
Origin
Unknown
First seen
2024
Last active
2024
Motivation
Financially motivated (ransomware)
Confidence
medium
MENA targeting
Israel, Saudi Arabia, UAE, Qatar, Oman
Sectors
Technology, business services, healthcare, financial services, transportation/logistics

Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.

Why it mattersRansomware actor, medium confidence, documented targeting Israel, Saudi Arabia, UAE (Technology, business services, healthcare sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.

DarkVault is a data-extortion and ransomware operation that surfaced in 2024 running a Tor leak site closely modeled on LockBit 3.0 and reportedly deploying payloads built from the leaked LockBit Black (LockBit 3.0) builder.

History

DarkVault first drew public attention in April 2024 (with some observations dating to late 2023) when it published data belonging to roughly 19 victims on a dedicated leak site (DLS) whose layout closely mirrored LockBit's. Researchers noted the group's reuse of the LockBit Black ransomware built from the 2022-leaked LockBit 3.0 builder, which fed rebranding rumors; however, no verified technical evidence links DarkVault to LockBit's core codebase, and builder reuse is common across many unrelated crews.

Operationally DarkVault behaves as a broad data broker and extortion outfit, publishing victim listings and stolen data via Tor. Because it leans on a leaked builder and copycat branding rather than a distinctive in-house toolkit, attribution and internal structure remain poorly characterized.

DarkVault's claimed victimology spans multiple regions. In a MENA context it has been associated with claimed targeting across Israel, Saudi Arabia, the UAE, Qatar and Oman. All such leak-site listings should be treated as unverified claims unless independently confirmed by a reputable source or the victim organization; DarkVault's public activity appears sparse after its 2024 burst, leaving its current operational status uncertain.

Notable campaigns

2024
Initial leak-site debut
Claimed roughly 19 victims on a LockBit-styled DLS in April 2024, spurring LockBit rebranding speculation (unconfirmed).

Claimed victims · 55 tracked

Leak-site postings via ransomware.live — claimed by the group, not confirmed breaches. Metadata only. MENA Ransomware Watch →

DateVictimCountrySector
yoniot.cnCNTechnology
confluxhr.comINTechnology
timely.mnMNTechnology
salesgig.comUSProfessional Services
inthinking.netKREducation
arabot.ioUAETechnology
techguard.inINTechnology
naj.aeUAETechnology
freshairefranchise.comUSProfessional Services
pocketrisk.comGBFinancial Services
ingotbrokers.comSCFinancial Services
peoplewell.comKRHealthcare