Uptime Hamster: 11d 8h 5mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza blacksuit

blacksuit

3 incidentes 1 paises 0 sectores ransomware RU Ultimo: 2026-06-29
Aliases: Ignoble Scorpius, Royal Ransomware
Ver en IntelTracker → APTTrail →
BlackSuit is a financially motivated ransomware group that emerged in April 2023, largely recognized as a rebrand or successor to the notorious Royal ransomware and possessing significant code similarities with the defunct Conti ransomware syndicate. Operating as a private entity rather than a Ransomware-as-a-Service (RaaS) model with public affiliates, BlackSuit distinguishes itself by targeting both Windows and Linux systems, including VMware ESXi servers. The group is known for its high ransom demands, typically ranging from $1 million to $10 million, with some instances reaching up to $60 million, and a unique approach to encryption that involves partial file encryption to enhance speed and evade detection. They notably avoid targeting entities within Commonwealth of Independent States (CIS) countries.

Aliases del actor

Ignoble ScorpiusRoyal Ransomware

Actores similares

royalransomware · 211lockbit3ransomware · 2016qilinransomware · 1933akiraransomware · 1524playransomware · 1268clopransomware · 1254lockbit2ransomware · 1002ransomhubransomware · 842incransomransomware · 832alphvransomware · 731

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
Repositoriounknowngithub.comBushidoUK ToolMatrix GroupProfiles: BlackSuit
Repositorioupgithub.comBushidoUK ToolMatrix CommunityReports: CR-015-BlackSuit-April-2024
X/Twitterunknownconnect.cybercx.com.auBushidoUK ToolMatrix GroupProfiles: BlackSuit
DLS / leak siteunknownwww.cisa.govBushidoUK ToolMatrix GroupProfiles: BlackSuit
Repositorioupgithub.comBushidoUK ToolMatrix CommunityReports: CR-015-BlackSuit-April-2024
DLS / leak siteupwww.darktrace.comBushidoUK ToolMatrix CommunityReports: CR-015-BlackSuit-April-2024
Repositoriounknowngithub.comRansom Notes: blacksuit (1 notes from ThreatLabz)
DLS / onionunknownweg7sdx54bevnvulapqu6bpzwztryeflq3s23tegbmnhkbpqz637f2yd.onionblacksuit
DLS / leak siteunknownransomware.anggipradana.comRansomware Group: blacksuit
Malware asociado
BlackSuit
Tecnicas MITRE
T1078, T1083, T1082, T1057, T1490, T1090
CVEs relacionadas
CVE-2025-49706, CVE-2025-49704
Victimas
1
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United States (1)

Paises objetivo (SOCRadar)

ArgentinaAustraliaBelgiumBrazilCanadaSwitzerlandChinaGermanyDenmarkEgypt

Sectores objetivo (SOCRadar)

Construction of BuildingsFood ManufacturingOther Information ServicesRail TransportationSoftware PublishersReal EstateHospitalsAccommodationAir TransportationManufacturing

URLs nuevas detectadas en IntelTracker

github.com ransomware.anggipradana.com

Victimas (1)

Ransom Notes: blacksuit (1 notes from ThreatLabz)18 Jun 2026
Report
blacksuit - Ransom NotesEste grupo de ransomware tiene 1 notas de rescate documentadas en el repositorio ThreatLabz/ransomware_notes. Las notas de res…