Back to Resources

SentinelOne Demo: SentinelOne VS Dark Power Ransomware – Detection and Response

In this video demo, we showcase how SentinelOne’s XDR technology detects and mitigates against Dark Power ransomware. Dark Power first emerged in early 2023. The ransomware group engages in multi-extortion, threatening to release victim’s data upon failure to comply with attacker demands. Dark Power is written in Nim, which is a multi-platform language.

Dark Power also has standard ransomware features such as VSS removal. Upon infection, a multi-page PDF file is dropped with victim instructions in in lieu of a traditional ransom note. Infected victims are instructed on how to engage the attacker via qTox, along with their .onion (blog address). In addition, the ransomware will attempt to terminate any processes that may inhibit the encryption of the device, a measure coded into the ransomware. The malware also clears out Windows event logs in an attempt to obfuscate its presence.

Dark Power requires victims to pay their extortion fees in XMR (Monero). Early campaigns featured ransom amounts of $10,000 USD.

Experience the power of SentinelOne’s XDR solution and witness first-hand its effectiveness in combating the Dark Power ransomware. Subscribe to our channels for more in-depth analysis and real-life examples from the forefront of cybersecurity.

Watch Now

Experience the World’s Most Advanced Cybersecurity Platform

See how our intelligent, autonomous cybersecurity platform harnesses the power of data and AI to protect your organization now and into the future.