Threat Assessment: Ignoble Scorpius, Distributors of BlackSuit Ransomware
ID: 92c41a4c-18e4-5cf5-9acf-bea13284b9bd
STIX ID: report--92c41a4c-18e4-5cf5-9acf-bea13284b9bd
Feed Name: Palo Alto Networks Unit 42
Unit 42 details a ramp-up in BlackSuit (Ignoble Scorpius) ransomware activity since its May 2023 rebrand of Royal, attributing at least 93 global victims and a preference for education, construction and manufacturing sectors. The report analyzes Windows and ESXi variants that append .blacksuit, describes initial access (phishing, GootLoader, supply-chain, stolen VPN creds), credential theft (Mimikatz, NanoDump, DCSync), lateral movement and persistence (RDP, SMB, PsExec, Cobalt Strike), data exfiltration (Rclone, Bublup, WinSCP), destructive impact (shadow copy deletion), and provides MITRE ATT&CK mappings, Cortex XDR XQL detections, IOCs (mutex, ransom note names) and mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
