logo

BlackSuit Ransomware

ID: 8fcd3386-7a8f-5979-8fed-20314e97d441

STIX ID: report--8fcd3386-7a8f-5979-8fed-20314e97d441

Feed Name: The DFIR Report

Threat Score
78/100

Date Published: 2024-08-26

Date Updated: 2026-04-19

Author: editor

...
...

In December 2023 a threat actor used Cobalt Strike (HTTP and SMB beacons proxied via CloudFlare/AWS), in-memory tooling (Rubeus, SharpHound), and SystemBC proxies to escalate, enumerate, and move laterally across an Active Directory environment; after harvesting credentials and mapping targets they distributed and executed BlackSuit ransomware (qwe.exe) via SMB and RDP, deleted shadow copies, and left ransom notes—this report documents the timeline, IoCs (hashes, domains, IPs), forensic artifacts, and detection rules.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.