CSIDB logo
Threat actor

Darkshadow

Attribution profile

Type
Terrorist
Location
United Kingdom
Known incidents
2 incidents
First seen
2015-01-02
Last seen
2015-07-15
Updated
2026-08-01 07:57
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Darkshadow is a threat actor known by the alias Darkshadow and is reported to be based in the United Kingdom. The actor has been linked to multiple cyber incidents that have been publicly attributed or associated with this name. No additional aliases or alternative identifiers are provided in the available sources.

The actor’s observed activities include targeting government websites and transportation infrastructure. In one incident, the official website of Pakistan’s president and seventy‑two other government sites were defaced, an act described as retaliation for prior cyberattacks by Pakistani hackers. In another incident, a United Kingdom bus operator’s timetable system was compromised by extremists who intended to disrupt Western transportation networks and cause travel chaos. These examples indicate that Darkshadow has focused on the government and transportation sectors, with objectives centered on disruption and retaliation rather than financial gain or espionage.

Public reporting does not specify any particular malware families, initial access vectors, or tooling styles used by Darkshadow. The summaries mention breaching a government proxy server and hacking into a timetable system, but they do not detail the methods, exploits, or tools employed. Consequently, no specific TTPs can be confirmed from the supplied material, and any discussion of malware or attack vectors would be speculative.

The actor has been associated with distinct groups in the reported incidents. The defacement of Pakistani government sites was carried out by Bangladeshi hackers identifying with the Blacksmith Hacker’s team, while the bus timetable breach was attributed to Islamist militants seeking to undermine Western logistical operations. These affiliations are presented as the responsible parties in the respective attacks, linking Darkshadow to both a hacker collective and an extremist militant network. Representative operations linked to Darkshadow include the 2015 defacement of the Pakistani presidential website and associated government portals, and the 2015 compromise of the United Kingdom bus operator’s timetable system, both of which were widely reported in open‑source news outlets.

Incidents

Attributed incidents are available to members.

2 incidents
CSIDB