Uptime Hamster: 22d 9h 21mDeploy: 3 Aug 2026 06:56Updated: 2026-07-21
Logo del actor de amenaza Blacktail

Blacktail

0 incidentes 0 paises 0 sectores apt CN Ultimo: -
Ver en IntelTracker → APTTrail →
Blacktail, also known as Buhti, is a ransomware operation that emerged in February 2023, distinguished by its rapid exploitation of newly disclosed vulnerabilities and its reliance on repurposed leaked ransomware code. While the group does not develop its own ransomware strains, it notably utilizes modified variants of the leaked LockBit 3.0 ransomware for Windows systems and Babuk ransomware for Linux and ESXi environments. A core characteristic that sets Blacktail apart is its development and deployment of a custom, Golang-based information stealer for data exfiltration, which complements its double extortion strategy. Symantec tracks this group under the name Blacktail, whereas other security researchers and the group's ransomware payload often refer to it as Buhti.
Tecnicas MITRE
T1105, T1566, T1082, T1027.002, T1071.001
Tipo
apt
Pais origen
CN
Motivacion
-
Impacto
5
Actualizado
Sat, 02 De

Sectores objetivo (OSINT)

National Security&International AffairsBanking