logo

BlackSuit Claims Dozens of Victims With Carefully Curated Ransomware

ID: e5e01479-3b48-55df-bcc2-f7a62e023816

STIX ID: report--e5e01479-3b48-55df-bcc2-f7a62e023816

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2024-05-29

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

ReliaQuest analyzed an April intrusion by the BlackSuit ransomware group—an offshoot of Royal/Conti actors—that targeted US critical-sector organizations, exfiltrated over 100 GB of data, and deployed ransomware to hundreds of hosts using tactics including VPN credential abuse, Kerberoasting, PsExec lateral movement, FTP exfiltration, and VM-based obfuscation; the group practices double-extortion and has leaked data from 53 organizations over a year. The report details the attack chain, detection and remediation actions taken, and mitigation recommendations to harden VPNs, logging, and Active Directory protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.