Black Suit
BlackSuit first appeared in May 2023 and is a confirmed rebrand or direct evolution of Royal Ransomware. It operates as a Ransomware-as-a-Service (RaaS), employing a double-extortion model—encrypting files and stealing sensitive data for leak threats. BlackSuit targets Windows and Linux systems, including VMware ESXi environments, using the .blacksuit extension for encrypted files. Technical analysis shows strong code overlaps (≈98%) with Royal, itself believed to be run by former Conti affiliates. Victims span healthcare, critical manufacturing, education, and government sectors, with notable incidents affecting public health systems in the U.S. Initial access vectors include phishing, exploitation of public-facing applications (e.g., Citrix and Fortinet vulnerabilities), and compromised credentials purchased from initial access brokers. Ransom notes direct victims to Tor-based negotiation portals.
Países más afectados
Sin datos todavía.
Sectores más afectados
Sin datos todavía.
Víctimas recientes
Sin datos todavía.
Las reivindicaciones las publican los propios grupos criminales y no están verificadas hasta que la organización o la prensa las confirman. Los nombres de personas físicas (autónomos, profesionales individuales) se anonimizan conforme al RGPD. Nunca enlazamos a sitios de filtración ni a datos robados. Para solicitar la retirada o anonimización de una entrada, contacte con el administrador del sitio.
Fuentes: RansomLook (CC BY 4.0), MITRE ATT&CK®, MISP Galaxy, Google News.