Blackout is a ransomware group that emerged in early 2024, initially targeting healthcare entities and later expanding its operations to various sectors including telecommunications, mining, and manufacturing. The group is financially motivated, employing a double extortion model where stolen data is published on a dedicated leak blog if ransom demands are not met. Blackout is known for developing and deploying its own ransomware and actively promoting its activities on underground forums to build notoriety and apply pressure on victims. This group is distinct from an older, open-source project also named 'BLACKOUT ransomware'.
Tecnicas MITRE
T1047, T1021.002, T1059.001, T1562.001, T1078.003
RansomLook pivots
Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.
Construction of BuildingsFood ManufacturingOther Information ServicesRail TransportationHospitalsEnterprises & HoldingAccommodationAir TransportationManufacturingConstruction