blackmatter logo

blackmatter

2 incidentes 0 paises 0 sectores ransomware RU Ultimo: 2026-06-25
Aliases: DarkSide
Ver en IntelTracker → APTTrail →
BlackMatter is a Ransomware-as-a-Service (RaaS) collective that emerged in mid-2021, filling the operational void left by the earlier disappearances of the DarkSide and REvil ransomware groups. The group quickly became known for targeting large organizations for significant financial gain through double extortion tactics. BlackMatter is widely assessed to be a Russian-speaking entity, consistently adhering to a policy of not targeting organizations within Russia or other Commonwealth of Independent States (CIS) countries. What distinguishes BlackMatter is its strategic amalgamation of the most effective features from DarkSide, REvil, and LockBit ransomware, creating a highly potent and adaptable threat. The group explicitly focused on entities with annual revenues exceeding $100 million and networks with 500 to 15,000 hosts, while controversially claiming to avoid critical infrastructure sectors such as healthcare, oil and gas pipelines, and government organizations. BlackMatter is con
Tecnicas MITRE
T1070.001, T1424, T1070, T1566, T1021, T1022

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Victimas
1
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises objetivo (SOCRadar)

AustriaAustraliaBrazilCanadaChileGermanyFranceUnited KingdomHong KongIndia

Sectores objetivo (SOCRadar)

Construction of BuildingsFood ManufacturingOther Information ServicesSoftware PublishersReal EstateAccommodationManufacturingConstructionElectrical Equipment, Appliance, and Component ManufacturingPublic Administration

URLs nuevas detectadas en IntelTracker

github.com ransomware.anggipradana.com

Victimas (1)

Ransom Notes: blackmatter (1 notes from ThreatLabz)18 Jun 2026
Report
blackmatter - Ransom NotesEste grupo de ransomware tiene 1 notas de rescate documentadas en el repositorio ThreatLabz/ransomware_notes. Las notas de r…