Law Enforcement Seizes BlackSuit Ransomware Servers Targeting U.S. Critical Infrastructure
ID: 720b80fe-1758-5b7d-8516-0006d9e2f26a
STIX ID: report--720b80fe-1758-5b7d-8516-0006d9e2f26a
Feed Name: GBHackers
Executive Summary: U.S. and international law enforcement agencies executed a coordinated takedown of the BlackSuit (formerly Royal) ransomware group, dismantling multiple C2 servers and domains and seizing roughly $1,091,453 in virtual currency. The advisory outlines BlackSuit’s TTPs — phishing, RDP exploitation, vulnerability chaining, Cobalt Strike beacons, credential dumping with Mimikatz, persistence mechanisms — and provides IOCs (malicious IPs, hashes, YARA rules) to help defenders detect and mitigate related activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
