BlackSuit is a financially motivated ransomware group that emerged in April 2023, largely recognized as a rebrand or successor to the notorious Royal ransomware and possessing significant code similarities with the defunct Conti ransomware syndicate. Operating as a private entity rather than a Ransomware-as-a-Service (RaaS) model with public affiliates, BlackSuit distinguishes itself by targeting both Windows and Linux systems, including VMware ESXi servers. The group is known for its high ransom demands, typically ranging from $1 million to $10 million, with some instances reaching up to $60 million, and a unique approach to encryption that involves partial file encryption to enhance speed and evade detection. They notably avoid targeting entities within Commonwealth of Independent States (CIS) countries.
Malware asociado
BlackSuit
Tecnicas MITRE
T1078, T1083, T1082, T1057, T1490, T1090
CVEs relacionadas
CVE-2025-49706, CVE-2025-49704
RansomLook pivots
Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.
Construction of BuildingsFood ManufacturingOther Information ServicesRail TransportationSoftware PublishersReal EstateHospitalsAccommodationAir TransportationManufacturing