Encryption algorithms found in a decryptor show that the notorious DarkSide ransomware gang has rebranded as a new BlackMatter ransomware operation. The group is actively attacking victims and purchasing network access from other threat actors to launch new attacks. One victim has already paid a $4 million ransom for deleting stolen data and receiving a Windows and Linux ESXi decryptor. The encryption routines used by the new group are pretty much the same, including a custom Salsa20 matrix that DarkSide had used in their attacks.
Source: https://www.bleepingcomputer.com/news/security/darkside-ransomware-gang-returns-as-new-blackmatter-operation/