HackerFeeds
All ransomware groups

blacksuit

184 tracked victims
·first seen 2023-06-12·last activity 2025-05-29

Group profile

According to Trend Micro, this ransomware has significant code overlap with Royal Ransomware.

MITRE ATT&CK TTPs

TA0001

Initial Access

  • T1021.001Remote Services: Remote Desktop Protocol

    BlackSuit actors use RDP compromise as a secondary initial access vector.

  • T1133External Remote Services

    BlackSuit actors gain initial access through a variety of RMM software.

  • T1190Exploit Public-Facing Application

    BlackSuit actors gain initial access through public-facing applications.

  • T1566Phishing

    BlackSuit criminals often obtain initial access to victim networks through phishing.

  • T1566.001Phishing: Spear phishing Attachment

    BlackSuit agents have used malicious PDF document attachments in phishing campaigns.

  • T1566.002Phishing: Spear phishing Link

    Actors gain initial access through malvertising links via emails and public websites.

TA0004

Privilege Escalation

  • T1078Valid Accounts

    BlackSuit actors used a legitimate administrator account to gain access privileges to the domain controller.

  • T1078.002Valid Accounts: Domain Accounts

    BlackSuit actors used encrypted files to create new administrator user accounts.

TA0005

Defense Evasion

  • T1021.001Remote Services: Remote Desktop Protocol

    BlackSuit actors used valid accounts to move laterally through the domain controller using RDP.

  • T1070.001Indicator Removal: Clear Windows Event Logs

    BlackSuit actors deleted shadow files and system and security logs after exfiltration.

  • T1119Automated Collection

    BlackSuit actors used registry keys to extract and collect files automatically.

  • T1484.001Domain Policy Modification: Group Policy Modification

    BlackSuit actors modified Group Policy Objects to bypass antivirus protocols.

  • T1562.001Impair Defenses: Disable or Modify Tools

    BlackSuit actors disabled antivirus protocols.

TA0011

Command and Control

  • T1105Ingress Tool Transfer

    BlackSuit actors used C2 infrastructure to download various tools.

  • T1572Protocol Tunneling

    BlackSuit actors used an encrypted SSH tunnel to communicate within the C2 infrastructure.

TA0040

Impact

  • T1486Data Encrypted for Impact

    BlackSuit actors encrypted data to identify which files were being used or locked by other applications.

  • T1490Inhibit System Recovery

    BlackSuit actors encrypted data to identify which files were being used or locked by other applications.

TA0042

Resource Development

  • T1650Acquire Access

    BlackSuit actors may leverage brokers to gain initial access.

Recent victims

showing 50 of 184
DateWebsite / victimSectorCountry
2025-04-15
kcac.com
Kansas City Aviation Centerwww.kcac.com
Transportation/LogisticsUS
2025-03-30
metromont.com
metromont.commetromont.com
ConstructionUS
2025-05-29
innsofaurora.com
Inns of Aurorawww.innsofaurora.com
Hospitality and TourismUS
2025-05-15
gloucesterva.gov
Gloucester County Virginiawww.gloucesterva.gov
Public SectorUS
2025-04-24
pacmet.com
Pacific Metallurgicalwww.pacmet.com
ManufacturingUS
2025-04-24
fortunesociety.org
The Fortune Societyfortunesociety.org
Public SectorUS
2025-02-04
mmwec.org
Massachusetts Municipal Wholesale Electricmmwec.org
EnergyUS
2025-03-29
dapope.com
dapope.comdapope.com
Not FoundUS
2025-03-29
orangeville.ca
Town of Orangevilleorangeville.ca
Public SectorCA
2024-08-31
midwest.com
midwest.commidwest.com
Business ServicesUS
2024-10-23
copresi.es
copresi.escopresi.es
Not FoundES
2024-10-11
jtekt-na.com
JTEKT NORTH AMERICAjtekt-na.com
ManufacturingUS
2024-10-08
gsd200.org
Grandview School Districtgsd200.org
EducationUS
2024-11-24
co.cullman.al.us
co.cullman.al.usco.cullman.al.us
Public SectorUS
2024-11-18
eastgateauto.com
eastgateauto.comeastgateauto.com
Transportation/LogisticsUS
2024-11-18
kciaviation.com
kciaviation.comkciaviation.com
Transportation/LogisticsUS
2024-11-17
hetrhedens.nl
hetrhedens.nlhetrhedens.nl
EducationNL
2024-10-02
brandywinecoachworks.com
brandywinecoachworks.combrandywinecoachworks.com
Transportation/LogisticsUS
2024-11-15
kapurinc.com
kapurinc.comkapurinc.com
Business ServicesIN
2024-11-15
klarenbeek-transport.nl
klarenbeek-transport.nlklarenbeek-transport.nl
Transportation/LogisticsNL
2024-10-09
surgicalassociates.com
surgicalassociates.comsurgicalassociates.com
HealthcareUS
2024-10-20
billyheromans.com
billyheromans.combillyheromans.com
Business ServicesUS
2024-11-15
kenmore.com
kenmore.comkenmore.com
Business ServicesUS
2024-10-28
marysville.k12.oh.us
marysville.k12.oh.usmarysville.k12.oh.us
EducationUS
2024-11-13
stalyhill-inf.tameside.sch.uk
stalyhill-inf.tameside.sch.ukstalyhill-inf.tameside.sch.uk
EducationGB
2024-10-07
steppingstonesd.org
steppingstonesd.orgsteppingstonesd.org
EducationUS
2024-11-12
jst.es
jst.esjst.es
TechnologyES
2024-11-12
jarrellinc.com
jarrellimc.comjarrellinc.com
Business ServicesUS
2024-11-11
supplytechnologies.com
Supply Technologiessupplytechnologies.com
Transportation/LogisticsUS
2024-11-11
maxxis.com
Maxxis Internationalmaxxis.com
ManufacturingVN
2024-11-11
dezinecorp.com
dezinecorp.comdezinecorp.com
Business ServicesCA
2024-11-02
svpworldwide.com
SVP Worldwidesvpworldwide.com
Business ServicesUS
2024-10-29
nathcompanies.com
nathcompanies.comnathcompanies.com
Hospitality and TourismUS
2024-10-05
wescan-services.com
wescan-services.com 760 GBwescan-services.com
Business ServicesCH
2024-10-05
wescan-services.com
wescan-services.comwescan-services.com
Business ServicesLU
2024-10-25
lolaliza.com
lolaliza.comlolaliza.com
Business ServicesBE
2024-10-25
deschampsimp.com
deschampsimp.comdeschampsimp.com
ManufacturingCA
2024-10-25
omara-ag.com
omara-ag.comomara-ag.com
Agriculture and Food ProductionDE
2024-10-25
nrcs.net
nrcs.netnrcs.net
TechnologyCH
2024-10-25
zyloware.com
zyloware.comzyloware.com
Business ServicesUS
2024-10-25
unitedsprinkler.com
unitedsprinkler.comunitedsprinkler.com
Business ServicesUS
2024-09-08
aerotecnic.com
Aerotecnicaerotecnic.com
ManufacturingES
2024-10-21
teddy.it
Teddy SpAteddy.it
Business ServicesIT
2024-10-19
rcschools.net
rcschools.netrcschools.net
EducationUS
2024-10-19
mopsohio.com
mopsohio.commopsohio.com
Transportation/LogisticsUS
2024-10-19
kchospice.org
Kansas City Hospicekchospice.org
HealthcareUS
2024-09-20
neighborscu.org
Neighbors Credit Unionneighborscu.org
Financial ServicesUS
2024-03-07
vra.com
Volta River Authorityvra.com
EnergyGH
2024-09-24
genproinc.com
GenPro Inc.genproinc.com
Transportation/LogisticsUS
2024-09-09
branhaven.com
Branhaven Chrysler Dodge Jeep Rambranhaven.com
Business ServicesUS