logo

BlackSuit Attack Analysis

ID: 2c8eaa99-39f4-519b-b74e-8858345a2b68

STIX ID: report--2c8eaa99-39f4-519b-b74e-8858345a2b68

Feed Name: ReliaQuest Blog

Threat Score
75/100

Date Published: 2024-05-28

Date Updated: 2026-04-29

...
...

ReliaQuest investigated an April 2024 BlackSuit ransomware attack that began with VPN account compromise and Kerberoasting, escalated to domain compromise (NTDS.DIT dump), exfiltration of over 100GB via FTP, and widespread encryption using PsExec and WMIC from a malicious VM; the report outlines the attack lifecycle, observed TTPs, indicators, containment/remediation actions, and recommended mitigations (MFA, EDR/logging, disabling weak Kerberos encryption, network segmentation, DLP).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.