logo

Threat Assessment: Ignoble Scorpius, Distributors of BlackSuit Ransomware

ID: 92c41a4c-18e4-5cf5-9acf-bea13284b9bd

STIX ID: report--92c41a4c-18e4-5cf5-9acf-bea13284b9bd

Feed Name: Palo Alto Networks Unit 42

Threat Score
78/100

Date Published: 2024-11-20

Date Updated: 2026-04-28

Author: Unit 42

...
...

Unit 42 details a ramp-up in BlackSuit (Ignoble Scorpius) ransomware activity since its May 2023 rebrand of Royal, attributing at least 93 global victims and a preference for education, construction and manufacturing sectors. The report analyzes Windows and ESXi variants that append .blacksuit, describes initial access (phishing, GootLoader, supply-chain, stolen VPN creds), credential theft (Mimikatz, NanoDump, DCSync), lateral movement and persistence (RDP, SMB, PsExec, Cobalt Strike), data exfiltration (Rclone, Bublup, WinSCP), destructive impact (shadow copy deletion), and provides MITRE ATT&CK mappings, Cortex XDR XQL detections, IOCs (mutex, ransom note names) and mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.