According to Trend Micro, this ransomware has significant code overlap with Royal Ransomware. Known victims: 184 1 ransom note(s) on file
Objectives
Executive Summary
Blacksuit is a medium-sophistication cybercriminal threat actor primarily involved in ransomware activities for financial gain. They were first observed on 2023-06-12 and last seen on 2025-05-29, targeting 184 victims. Blacksuit's ransomware shares code similarities with Royal Ransomware, suggesting potential use of similar tactics such as phishing emails and exploit kits. Their operations are detectable through known IP addresses used in command and control communications.
Goals & Targeting
Blacksuit's primary goal is financial gain through ransomware operations. They target a broad range of potential victims, likely selecting based on susceptibility rather than specific sectors or regions. The group's targeting approach suggests they may aim for organizations with high data value to maximize the potential payout when encrypting systems.
Enhanced Description
Blacksuit is a cybercriminal threat group leveraging ransomware to achieve financial gains. Their activities began in mid-2023, with ongoing operations observed up until May 2025. The group's ransomware exhibits significant code overlap with Royal Ransomware, indicating a potential operational connection or inspiration from that known adversary. Blacksuit's victims include 184 individuals or organizations, though no specific sector has been targeted more than others yet. Their strategy likely involves phishing campaigns to distribute their malware, aiming for systems to encrypt and demand payment for decryption keys. The detection of their activity can be challenging but is aided by identifying hardcoded IP addresses in their command and control infrastructure.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Blacksuit has conducted campaigns targeting numerous victims, with patterns suggesting a focus on deploying ransomware through phishing emails and exploiting vulnerabilities. While their exact campaign tactics are not fully documented beyond the known victims and sample IP, they likely follow well-known methods used in similar threats. Their operational tempo has been moderate but persistent, with notable activity peaks based on the provided timeline.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence in Blacksuit's profile is moderate based on the provided data. While their operational connection to Royal Ransomware suggests shared TTPs, limited details about specific campaigns or tools mean that some aspects of their behavior are still unclear.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
1
IOCs
0
Observed Data
0
Tactics