logo

Deep Dive: Exposing Stealthy New BlackSuit Ransomware

ID: 518fa2e5-3a24-53ff-b3a0-2ca5c7fbf10e

STIX ID: report--518fa2e5-3a24-53ff-b3a0-2ca5c7fbf10e

Feed Name: Deep Instinct Blog

Threat Score
80/100

Date Published: 2024-07-17

Date Updated: 2026-04-27

Author: Ivan Kosarev

...
...

This report documents the BlackSuit ransomware campaign: describing executable masking, supported command-line options (encryption modes, VM-killing, self-deletion, partial encryption), destructive actions (vssadmin shadow deletion), common infection vectors (RDP, VPN/firewall exploits, malicious attachments, torrents, malicious ads), associated offensive tools (Cobalt Strike, Mimikatz, Rclone, etc.), a public leak site for exfiltrated data, and multiple IOCs (file hashes, ransom note filenames, mutex) to aid detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.