Uptime Hamster: 21d 9h 2mDeploy: 3 Aug 2026 06:56Updated: 2026-07-21
Logo del actor de amenaza blackout

blackout

4 incidentes 3 paises 2 sectores threat-actor RU Ultimo: 2026-07-19
Aliases: Blackoutware
Ver en IntelTracker → APTTrail →
Blackout is a ransomware group that emerged in early 2024, initially targeting healthcare entities and later expanding its operations to various sectors including telecommunications, mining, and manufacturing. The group is financially motivated, employing a double extortion model where stolen data is published on a dedicated leak blog if ransom demands are not met. Blackout is known for developing and deploying its own ransomware and actively promoting its activities on underground forums to build notoriety and apply pressure on victims. This group is distinct from an older, open-source project also named 'BLACKOUT ransomware'.

Aliases del actor

Blackoutware

Actores similares

Blackoutwareransomware · 0

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / leak siteunknownduckduckgo.comyano.tokyo
DLS / leak siteunknownduckduckgo.comyano.tokyo
DLS / leak siteunknownduckduckgo.comwww.miatech.net
DLS / leak siteunknownduckduckgo.comwww.miatech.net
DLS / leak siteunknownransomware.anggipradana.comRansomware Group: blackout
Forounknownnitter.netDaily Dark Web: French Hospital Patient Database Allegedly Repackaged and Shared A threat actor has published what they claim is a reformatted dataset originating from the 2024 Blackout ransomware leak targeting Centre Hospitalier d'Armentières in France. According to the post, the dataset contains information on approximately 203,928 patients, covering records from 2004 through March 2018.
Forounknownx.comDaily Dark Web: French Hospital Patient Database Allegedly Repackaged and Shared A threat actor has published what they claim is a reformatted dataset originating from the 2024 Blackout ransomware leak targeting Centre Hospitalier d'Armentières in France. According to the post, the dataset contains information on approximately 203,928 patients, covering records from 2004 through March 2018.
DLS / onionunknownblack3gnkizshuynieigw6ejgpblb53mpasftzd6pydqpmq2vn2xf6yd.onionmarktsec
Tecnicas MITRE
T1047, T1021.002, T1059.001, T1562.001, T1078.003
Victimas
2
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

Japan (1) United States (2) Germany (1)

Paises objetivo (OSINT)

BrazilCanadaChinaGermanySpainFranceGreeceCroatiaJapanMexico

Sectores atacados

Technology (2) Healthcare (1)

Sectores objetivo (OSINT)

Construction of BuildingsFood ManufacturingOther Information ServicesRail TransportationHospitalsEnterprises & HoldingAccommodationAir TransportationManufacturingConstruction

URLs nuevas detectadas en IntelTracker

duckduckgo.com duckduckgo.com duckduckgo.com duckduckgo.com ransomware.anggipradana.com

Victimas (2)

yano.tokyo19 Jul 2026
Ransomware Japan Technology
Resumen Una alerta de ransomware ha sido registrada relacionada con la empresa Yano Electronics Ltd., identificada como una organización en el campo d…
www.miatech.net19 Jul 2026
Ransomware United States Technology
Resumen El 19 de julio de 2026, la empresa Miatech, una compañía estadounidense que ofrece servicios de viaje para pasajeros, fue objeto de un ataque …