logo

BlackSnake Ransomware: Rising From Chaos' Shadow

ID: 2a706a9a-dbce-558b-9df5-4aeb54b50d37

STIX ID: report--2a706a9a-dbce-558b-9df5-4aeb54b50d37

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2025-11-13

Date Updated: 2026-07-16

...
...

This report analyzes the BlackSnake ransomware, a .NET 32-bit family derived from Chaos ransomware that combines traditional file-encrypting ransomware behavior with an integrated clipper module that monitors the clipboard for cryptocurrency addresses and replaces them with attacker-controlled addresses. The analysis covers execution flow (locale checks and anti-duplication), persistence via %appdata% svchost.exe and registry Run key, targeted file extensions and exclusions, encryption routine (random 40-byte string, AES encryption with RSA-encrypted key appended), ransom note delivery (UNLOCK_MYFiles.txt with TOX contact), and provides IOCs and recommended mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.