logo

Dissecting BlackMatter Ransomware

ID: 30fc5ebd-ceb0-5ddb-92a8-26b6ad55d9cd

STIX ID: report--30fc5ebd-ceb0-5ddb-92a8-26b6ad55d9cd

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2025-05-12

Date Updated: 2026-07-20

...
...

BlackMatter ransomware — Cyble Research Lab provides a concise technical dissection of the BlackMatter ransomware and actor: compilation and import/API usage, mutex and multi-threaded execution, deletion of volume shadow copy services, file encryption (appending random extensions), ransom notes and wallpaper changes, C2 communications with encrypted system JSON, and listed IOCs (multiple SHA-256 hashes, C2 domains and a TOR contact). The report includes ATT&CK mappings and mitigation recommendations such as MFA, patching, AV protection, and offline backups.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.