Deep Dive: Exposing Stealthy New BlackSuit Ransomware
ID: 518fa2e5-3a24-53ff-b3a0-2ca5c7fbf10e
STIX ID: report--518fa2e5-3a24-53ff-b3a0-2ca5c7fbf10e
Feed Name: Deep Instinct Blog
This report documents the BlackSuit ransomware campaign: describing executable masking, supported command-line options (encryption modes, VM-killing, self-deletion, partial encryption), destructive actions (vssadmin shadow deletion), common infection vectors (RDP, VPN/firewall exploits, malicious attachments, torrents, malicious ads), associated offensive tools (Cobalt Strike, Mimikatz, Rclone, etc.), a public leak site for exfiltrated data, and multiple IOCs (file hashes, ransom note filenames, mutex) to aid detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
