Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors blackout

Description

Blackout is a ransomware group that first appeared in early 2024, initially claiming attacks against healthcare entities in Canada, France, and Germany before expanding to telecommunications, mining, and manufacturing sectors, operating a double-extortion model with a data leak site. Known victims: 9

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

Blackout is a ransomware group active since early 2024, targeting primarily healthcare and later expanding to telecommunications, mining, and manufacturing sectors across multiple countries. They operate using a double extortion model, encrypting victim data and threatening泄露 unless ransoms are paid.

Goals & Targeting

Blackout's primary objectives are financial gain through ransom payments and the disruption of targeted organizations' operations. They appear to focus on sectors where operational downtime can lead to significant revenue loss or regulatory scrutiny, such as healthcare. Their targeting strategy suggests an interest in geographies with a mix of institutional vulnerabilities and economic potential, including North America, Europe, and parts of Asia. Typical victims are medium to large enterprises with weaker cybersecurity postures, though recent activity indicates they may be expanding their scope to include smaller businesses.

Enhanced Description

Blackout emerged in early 2024, initially making headlines through attacks on healthcare entities in Canada, France, and Germany. The group has since diversified its targets to include telecommunications, mining, and manufacturing sectors, employing a double extortion strategy that combines ransomware deployment with data exfiltration and leak threats. This approach increases pressure on victims to comply, as reputational damage can follow financial loss. Blackout's operational timeline spans from 2024 to at least mid-2026, indicating sustained campaign activity across multiple industries. The group leverages sophisticated tactics to infiltrate networks, deploy their ransomware, and maintain persistence, adhering to a pattern that balances profitability with avoiding detection.

Key Capabilities

  • Ransomware deployment
  • Data exfiltration and leak site operations
  • Double extortion tactics
  • Email phishing campaigns with malicious attachments
  • Sophisticated network persistence techniques

MITRE ATT&CK Tactics

Exfiltration
Encryption
Credential Access
Disruption
Defense-Evasion

ATT&CK Techniques

T1059.003
T1078.002
T1046.004
T1070
T1566.001

Software / Tooling

Custom ransomware family
Phishing toolset with macro-laced documents
C2 infrastructure (e.g., domains like yano.tokyo)

Campaigns & Victims

Blackout's campaigns exhibit a pattern of initial attacks on high-value targets in regulated sectors, then expanding to broader industries. Their operational tempo is steady but not rapid, suggesting careful targeting and patiententerprise compromise. Known campaigns include operations against yano.tokyo, miatech.net, and bluebellgroup.com, indicating a focus on corporate websites for potentially strategic C2 communication points.

IOC Patterns

  • Spear-phishing emails with malicious Office attachments
  • Ransomware-related file encryption (e.g., .blackout extension)
  • C2 communications via known domains like yano.tokyo
  • Lateral movement within the network using common protocols
  • Web traffic spikes on targeted sites during campaigns

Recommended Actions

  • Implement robust email filtering to detect phishing attempts
  • Enhance endpoint detection and response capabilities
  • Regularly back up critical systems and store backups offline
  • Monitor for unusual authentication or file activity
  • Conduct employee training on recognizing ransomware threats

Suggested Tags

Ransomware
CyberCrime
Double-Extortion
Financial-Gain
Healthcare Targeting

Confidence Assessment

The available data on Blackout is moderately confident, with clear indications of their activities since early 2024. Some gaps exist in the specifics of their TTPs and exact toolset, as well as the full extent of their global operations.

Intel Summary

0

Techniques

0

Tools

3

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Healthcare Targeting
CyberCrime
Double-Extortion
Financial-Gain

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Feb 26, 2024
Last Seen
Jul 19, 2026
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.