logo

BlackSuit: A Hybrid Approach with Data Exfiltration and Encryption

ID: e9476633-6611-549f-8fae-26642dbeb87f

STIX ID: report--e9476633-6611-549f-8fae-26642dbeb87f

Feed Name: Cybereason Blog

Threat Score
80/100

Date Published: 2025-07-11

Date Updated: 2026-04-27

Author: Cybereason Security Services Team

...
...

**Executive summary:** This Cybereason Threat Analysis documents a multi-stage BlackSuit ransomware operation that leveraged Cobalt Strike for C2 and lateral movement, renamed rclone for exfiltration (~60 GB observed), and a BlackSuit payload that deleted shadow copies and encrypted files while dropping ransom notes; the report provides IOCs (hashes, IPs, domains), MITRE ATT&CK mappings, and remediation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.