BlackSuit Ransomware
ID: 8fcd3386-7a8f-5979-8fed-20314e97d441
STIX ID: report--8fcd3386-7a8f-5979-8fed-20314e97d441
Feed Name: The DFIR Report
In December 2023 a threat actor used Cobalt Strike (HTTP and SMB beacons proxied via CloudFlare/AWS), in-memory tooling (Rubeus, SharpHound), and SystemBC proxies to escalate, enumerate, and move laterally across an Active Directory environment; after harvesting credentials and mapping targets they distributed and executed BlackSuit ransomware (qwe.exe) via SMB and RDP, deleted shadow copies, and left ransom notes—this report documents the timeline, IoCs (hashes, domains, IPs), forensic artifacts, and detection rules.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
