BlackSuit: A Hybrid Approach with Data Exfiltration and Encryption
ID: e9476633-6611-549f-8fae-26642dbeb87f
STIX ID: report--e9476633-6611-549f-8fae-26642dbeb87f
Feed Name: Cybereason Blog
Threat Score
**Executive summary:** This Cybereason Threat Analysis documents a multi-stage BlackSuit ransomware operation that leveraged Cobalt Strike for C2 and lateral movement, renamed rclone for exfiltration (~60 GB observed), and a BlackSuit payload that deleted shadow copies and encrypted files while dropping ransom notes; the report provides IOCs (hashes, IPs, domains), MITRE ATT&CK mappings, and remediation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
