Blackout is a ransomware group that first appeared in early 2024, initially claiming attacks against healthcare entities in Canada, France, and Germany before expanding to telecommunications, mining, and manufacturing sectors, operating a double-extortion model with a data leak site. Known victims: 9
Objectives
Executive Summary
Blackout is a ransomware group active since early 2024, targeting primarily healthcare and later expanding to telecommunications, mining, and manufacturing sectors across multiple countries. They operate using a double extortion model, encrypting victim data and threatening泄露 unless ransoms are paid.
Goals & Targeting
Blackout's primary objectives are financial gain through ransom payments and the disruption of targeted organizations' operations. They appear to focus on sectors where operational downtime can lead to significant revenue loss or regulatory scrutiny, such as healthcare. Their targeting strategy suggests an interest in geographies with a mix of institutional vulnerabilities and economic potential, including North America, Europe, and parts of Asia. Typical victims are medium to large enterprises with weaker cybersecurity postures, though recent activity indicates they may be expanding their scope to include smaller businesses.
Enhanced Description
Blackout emerged in early 2024, initially making headlines through attacks on healthcare entities in Canada, France, and Germany. The group has since diversified its targets to include telecommunications, mining, and manufacturing sectors, employing a double extortion strategy that combines ransomware deployment with data exfiltration and leak threats. This approach increases pressure on victims to comply, as reputational damage can follow financial loss. Blackout's operational timeline spans from 2024 to at least mid-2026, indicating sustained campaign activity across multiple industries. The group leverages sophisticated tactics to infiltrate networks, deploy their ransomware, and maintain persistence, adhering to a pattern that balances profitability with avoiding detection.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Blackout's campaigns exhibit a pattern of initial attacks on high-value targets in regulated sectors, then expanding to broader industries. Their operational tempo is steady but not rapid, suggesting careful targeting and patiententerprise compromise. Known campaigns include operations against yano.tokyo, miatech.net, and bluebellgroup.com, indicating a focus on corporate websites for potentially strategic C2 communication points.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The available data on Blackout is moderately confident, with clear indications of their activities since early 2024. Some gaps exist in the specifics of their TTPs and exact toolset, as well as the full extent of their global operations.
No techniques linked yet.
No tools linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
3
Campaigns
0
IOCs
0
Observed Data
0
Tactics