According to the FBI, DarkSide is a "cyber-criminal gang" based in Russia and Eastern Europe that operates a business model it describes as "ransomware as a service." The group announced in August 2020 that it had developed "ransomware tools" that it would sell to other hacking groups.
Since then, there have been 90 ransomware attacks that resulted in the theft of more than 2 terabytes of data. It is not clear whether these ransom attacks were staged exclusively by the DarkSide hacker group or by others using the DarkSide hacker tools. Most likely, it is a combination of both.
Following the attack, DarkSide announced that it was dissolving. However on May 12, it disclosed that three more companies, "a construction company in Scotland, a renewable energy product reseller in Brazil and a technology service reseller in the US," had been breached. A division of Toshiba's European unit, as well as Ireland's Health Service, have also been attacked.
It's not clear whether these attacks were staged by DarkSide, by groups affiliated with them or hackers using their tools. DarkSide has historically operated a sophisticated affiliate network where it shares the proceeds of its ransomware with partners that can facilitate its penetration of a victim's computer system.
Colonial Pipeline has confirmed that it paid a ransom of $4.4 million to regain control of its computer system. It's possible that Colonial Pipeline paid other sums not classified as ransom, but it is certain that a ransom was paid
According to DarkSide, some unknown entity subsequently raided the group's "digital wallet" where its cryptocurrency was kept and drained its $5.3 million contents. It's not clear who was responsible for taking DarkSide's cryptocurrency. Some commentators suggested that it was the U.S. government, although the Biden administration has denied this. It might also have been a ruse by DarkSide to deflect regulatory scrutiny and retaliation.
The use of Bitcoin to pay the ransom has rekindled concerns that cryptocurrencies pose a threat to U.S. national security, both because their use in ransomware attacks could encourage this activity but also, more generally, because they could potentially undermine the role of the U.S. dollar in the world's financial system.
How Do Digital Currencies Pose a National Security Threat to the US?
There are three ways in which crypto currencies could impact U.S. national security.
First, Bitcoin and other digital currencies are easier to "launder" than cash, i.e., move around and convert into other assets. Had DarkSide asked for cash or for the money to be wired to a foreign bank, it would have been far easier to track where the money was going.
Moving large quantities of cash without government sanction is difficult. Just try to buy a car, much less a house, for cash. Likewise, even if a foreign bank had been willing to accept and process the wire transfer, any financial institutions that participated in the transaction without regulatory approval would find themselves frozen out of the SWIFT network.
SWIFT stands for Society for Worldwide Interbank Financial Telecommunication, legally S.W.I.F.T. SCRL. It "provides a network that enables financial institutions worldwide to send and receive information about financial transactions in a secure, standardized and reliable environment." A bank frozen out of the SWIFT network could not deal with other banks and would find it impossible to operate internationally or do much more than provide local banking services.
A comparable regulatory structure for digital currencies has not yet evolved. More regulation is coming but, since digital currencies can be transferred directly through peer-to-peer networks, regulatory agencies may never have the degree of control over digital currencies that they do over electronic financial transactions involving conventional currencies.
By making it easier to monetize criminal activity, the rise of digital currencies may lead to an increase in criminal activity, especially activity like ransomware that can be conducted remotely. While any one activity may not rise to the level of a national security threat, the possibility of an overall increase in criminality does -- especially when those criminal acts are being conducted by foreign bad actors against American companies, U.S. government agencies or elements of critical American infrastructure.
Source - https://www.military.com/daily-news/opinions/2021/06/01/are-cryptocurrencies-threat-us-national-security.html