BlackSuit Claims Dozens of Victims With Carefully Curated Ransomware
ID: e5e01479-3b48-55df-bcc2-f7a62e023816
STIX ID: report--e5e01479-3b48-55df-bcc2-f7a62e023816
Feed Name: Dark Reading
Date Published: 2024-05-29
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
ReliaQuest analyzed an April intrusion by the BlackSuit ransomware group—an offshoot of Royal/Conti actors—that targeted US critical-sector organizations, exfiltrated over 100 GB of data, and deployed ransomware to hundreds of hosts using tactics including VPN credential abuse, Kerberoasting, PsExec lateral movement, FTP exfiltration, and VM-based obfuscation; the group practices double-extortion and has leaked data from 53 organizations over a year. The report details the attack chain, detection and remediation actions taken, and mitigation recommendations to harden VPNs, logging, and Active Directory protections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
