Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors blacksuit

Description

According to Trend Micro, this ransomware has significant code overlap with Royal Ransomware. Known victims: 184 1 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

Blacksuit is a medium-sophistication cybercriminal threat actor primarily involved in ransomware activities for financial gain. They were first observed on 2023-06-12 and last seen on 2025-05-29, targeting 184 victims. Blacksuit's ransomware shares code similarities with Royal Ransomware, suggesting potential use of similar tactics such as phishing emails and exploit kits. Their operations are detectable through known IP addresses used in command and control communications.

Goals & Targeting

Blacksuit's primary goal is financial gain through ransomware operations. They target a broad range of potential victims, likely selecting based on susceptibility rather than specific sectors or regions. The group's targeting approach suggests they may aim for organizations with high data value to maximize the potential payout when encrypting systems.

Enhanced Description

Blacksuit is a cybercriminal threat group leveraging ransomware to achieve financial gains. Their activities began in mid-2023, with ongoing operations observed up until May 2025. The group's ransomware exhibits significant code overlap with Royal Ransomware, indicating a potential operational connection or inspiration from that known adversary. Blacksuit's victims include 184 individuals or organizations, though no specific sector has been targeted more than others yet. Their strategy likely involves phishing campaigns to distribute their malware, aiming for systems to encrypt and demand payment for decryption keys. The detection of their activity can be challenging but is aided by identifying hardcoded IP addresses in their command and control infrastructure.

Key Capabilities

  • Ransomware deployment via phishing
  • Use of exploit kits for initial access
  • Encryption of victim data
  • Command and control infrastructure using hardcoded IPs

MITRE ATT&CK Tactics

Initial Access
Execution
Data Encirclement
Impact

ATT&CK Techniques

T1500.001
T1070
T1233
T1548

Software / Tooling

RoyalRAT
Phishing Email Kits (e.g., for spear-phishing)
Exploit Kit (for payload delivery)
Custom Ransomware
Hardcoded C2 IP Tools

Campaigns & Victims

Blacksuit has conducted campaigns targeting numerous victims, with patterns suggesting a focus on deploying ransomware through phishing emails and exploiting vulnerabilities. While their exact campaign tactics are not fully documented beyond the known victims and sample IP, they likely follow well-known methods used in similar threats. Their operational tempo has been moderate but persistent, with notable activity peaks based on the provided timeline.

IOC Patterns

  • Use of hardcoded C2 IPs (e.g., 104.244.75.168)
  • Phishing emails with malicious attachments
  • Lateral movement within a network post-compromise
  • Ransomware encryption of critical files

Recommended Actions

  • Implement multi-layered email filtering to detect phishing attempts
  • Monitor network traffic for connections to known C2 IPs and domains
  • Regularly back up data and store backups offline
  • Patch systems promptly to mitigate exploit risks
  • Use endpoint detection and response (EDR) tools for early threat detection

Suggested Tags

crime
ransomware
malware
financial-gain
organizational-gain

Confidence Assessment

The confidence in Blacksuit's profile is moderate based on the provided data. While their operational connection to Royal Ransomware suggests shared TTPs, limited details about specific campaigns or tools mean that some aspects of their behavior are still unclear.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

IPv4 Address 1

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

1

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
crime
ransomware
malware
financial-gain
organizational-gain

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Jun 12, 2023
Last Seen
May 29, 2025
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.