BL

Blacksuit Ransomware

Tracked

Threat actor group tracked in the global ransomware database · Last disclosure: Jun 2, 2025

Ransomware-as-a-Service (RaaS) Double Extortion Target: Business Services
165
Total Victims
0.8% of all tracked
20
Countries Targeted
13
Sectors Targeted
2024
First Seen

ThreatAI Analysis

Compiled from the ransomware.live profile for Blacksuit and from this database. Figures and technique mappings are quoted from the source data, not inferred.

Blacksuit has been responsible for attacks on 165 companies across 20 countries, targeting sectors like Business Services, Healthcare, and Manufacturing.

Recorded activity

Disclosures attributed to Blacksuit in this database run from January 2024 to June 2025, totalling 165 victims — 0.8% of everything tracked here. Blacksuit has listed victims in 20 countries in this database, most often United States, followed by United Kingdom and Canada. The sectors appearing most in its listings are Business Services, Healthcare, Manufacturing.

How Blacksuit is documented to operate

External Remote Services T1133 Persistence Initial Access

Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally. Access to Valid Accounts to use the service is often a requirement, which could be obtained through credential pharming or by obtaining the credentials from users after compromising the enterprise network.

Mitigations: Limit Access to Resource Over Network, Restrict Web-Based Content, Network Segmentation, Multi-factor Authentication, Disable or Remove Feature or Program

MITRE ATT&CK reference →
Exploit Public-Facing Application T1190 Initial Access

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration. Exploited applications are often websites/web servers, but can also include databases (like SQL), standard services (like SMB or SSH), network device administration and management protocols (like SNMP and Smart Install), and any other system with Internet-accessible open sockets. On ESXi infrastructure, adversaries may exploit exposed OpenSLP services; they may alternatively exploit exposed VMware vCenter servers.

Mitigations: Vulnerability Scanning, Limit Access to Resource Over Network, Filter Network Traffic, Network Segmentation, Privileged Account Management, Application Isolation and Sandboxing

MITRE ATT&CK reference →
Phishing T1566 Initial Access

Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass malware spam campaigns. Adversaries may send victims emails containing malicious attachments or links, typically to execute malicious code on victim systems. Phishing may also be conducted via third-party services, like social media platforms.

Mitigations: Network Intrusion Prevention, Restrict Web-Based Content, User Training, Antivirus/Antimalware, Software Configuration, Audit

MITRE ATT&CK reference →
Valid Accounts T1078 Stealth Persistence

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network.

Mitigations: Application Developer Guidance, User Training, Password Policies, User Account Management, Privileged Account Management, Multi-factor Authentication

MITRE ATT&CK reference →
Automated Collection T1119 Collection

Once established within a system or network, an adversary may use automated techniques for collecting internal data. Methods for performing this technique could include use of a Command and Scripting Interpreter to search for and copy information fitting set criteria such as file type, location, or name at specific time intervals. In cloud-based environments, adversaries may also use cloud APIs, data pipelines, command line interfaces, or extract, transform, and load (ETL) services to automatically collect data. This functionality could also be built into remote access tools.

Mitigations: Remote Data Storage, Encrypt Sensitive Information

MITRE ATT&CK reference →

MITRE ATT&CK techniques attributed to Blacksuit across its recorded activity. They describe the group overall, not any single incident.

Tooling observed in Blacksuit operations

  • AccountRestore
  • Mimikatz
  • NirSoft Dialupass
  • NirSoft MailPassView
  • NirSoft Netpass
  • NirSoft RouterPassView
  • Eraser
  • GMER
  • Inno Setup
  • PowerTool
  • VirtualBox
  • AdFind

Software reported in use by Blacksuit. Most are legitimate administration or transfer utilities; their presence in an environment is a signal to investigate, not proof of compromise.

Indicators of compromise

  • 104.244.75.168

Showing a sample of 1 IP on file. Hashes and network indicators published for Blacksuit. Leak-site addresses are deliberately excluded. Indicators age quickly — treat a match as a starting point for investigation, and an absence of matches as no assurance.

YARA detection rules

blacksuit.yar
rule RAN_Blacksuit_May_2023_1 : ransomware blacksuit esxi
{
    meta:
        description = "Detect the ESXI variant of Blacksuit ransomware"
        author = "Arkbird_SOLG"
        date = "2023-05-03"
        reference1 = "https://twitter.com/malwrhunterteam/status/1653743100605394947"
        reference2 = "https://twitter.com/Unit42_Intel/status/1653760405792014336"
        hash1 = "1c849adcccad4643303297fb66bfe81c5536be39a87601d67664af1d14e02b9e"
        // ref royal ransomware group ? 
        //hash2 = "09a79e5e20fa4f5aae610c8ce3fe954029a91972b56c6576035ff7e0ec4c1d14"
        //hash3 = "06abc46d5dbd012b170c97d142c6b679183159197e9d3f6a76ba5e5abf999725"
        //hash4 = "b64acb7dcc968b9a3a4909e3fddc2e116408c50079bba7678e85fee82995b0f4"
        //hash5 = "b57e5f0c857e807a03770feb4d3aa254d2c4c8c8d9e08687796be30e2093286c"
        tlp = "Clear"
        adversary = "-"
    strings:
        $s1 = { 48 8d 4c 24 0c 41 b8 04 00 00 00 ba 01 00 00 00 be 06 00 00 00 89 df e8 [3] ff 85 c0 0f 85 01 01 00 00 4c 89 e7 e8 59 c3 ff ff 4c 89 e7 89 c5 e8 2f c3 ff ff 89 df 89 ea 48 89 c6 e8 [3] ff 89 c7 b8 01 00 00 00 }
        $s2 = { 48 8b 7f 28 e8 [2] f4 ff 48 8d 35 [2] 0b 00 48 8d 3d [2] 0b 00 c7 05 [3] 00 01 00 00 00 e8 [3] ff 48 85 c0 48 89 05 [3] 00 0f 84 ed 00 00 00 48 8d 35 [2] 0b 00 48 8d 3d [2] 0b 00 e8 [3] ff 48 85 c0 48 89 05 [3] 00 0f 84 e2 00 00 00 48 8b 3d [3] 00 e8 [3] ff 48 8d 35 [3] 00 89 c7 e8 [3] ff 89 c2 b8 01 00 }
        $s3 = { 48 8d 85 30 fa ff ff ba 00 04 00 00 be 00 00 00 00 48 89 c7 e8 [2] ff ff 48 8d 95 30 fe ff ff 48 8d 85 30 fa ff ff be [2] 58 00 48 89 c7 b8 00 00 00 00 e8 [2] ff ff e8 [2] ff ff 89 45 c8 83 7d c8 00 75 }
        $s4 = { 89 ce 48 83 ec 18 48 89 d3 e8 20 ff ff ff 48 85 c0 49 89 c4 74 2a 48 8d 35 [3] 00 48 89 ea 48 89 c7 e8 26 fd ff ff 85 c0 74 32 48 85 db 74 0f 48 89 de 4c 89 e7 e8 92 fe ff ff 85 c0 74 1e 4c 89 e0 48 8b 1c 24 48 8b 6c 24 08 4c 8b 64 24 10 }
        // Remove it if you want a global esxi rule for Royal/Icefire/BlackSuit
        $s5 = { 70 73 20 2d 43 63 7c 67 72 65 70 20 76 6d 73 79 73 6c 6f 67 64 }
    condition:
       uint32(0) == 0x464C457F and filesize > 300KB and all of ($s*) 
}

Community-contributed rules for Blacksuit, reproduced as published. Test them against your own corpus before relying on them: rule quality and false-positive behaviour vary by author.

Threat Actor Analysis

Blacksuit is a ransomware threat group that has disclosed 165 victims in publicly accessible leak site data, representing 0.8% of all ransomware attacks tracked in this database. The earliest victim disclosure attributed to Blacksuit in our dataset dates to January 2024.

Geographically, Blacksuit has targeted organisations in 20 countries. The most frequently targeted nation is United States with 109 victim organisations. Other heavily targeted nations include United Kingdom, Canada, Spain.

Industry-wise, Blacksuit shows a concentration in the Business Services, Healthcare, Manufacturing sectors. These industries are frequently targeted because they manage sensitive data, critical operations, or have lower tolerance for operational downtime — conditions that increase ransom payment likelihood.

Like most modern ransomware operations, Blacksuit likely employs a double extortion model: encrypting victim files while simultaneously exfiltrating data, creating dual pressure to pay the ransom. Victim organisations that refuse payment face having their data published on the group's dark web leak site.

Note: This profile is generated from public leak site disclosures aggregated via the ransomware.live API. Data is updated automatically. The table below lists the 100 most recent of the 165 disclosures we hold for this group; use the link beneath it to page through all of them.

Recent Victim Disclosures (showing 100 of 165)

# Organization Country Sector Date
1 Kansas City Aviation Center www.kcac.com 🇺🇸 United States Transportation/Logistics Jun 2, 2025
2 Inns of Aurora www.innsofaurora.com 🇺🇸 United States Hospitality and Tourism May 29, 2025
3 metromont.com metromont.com 🇺🇸 United States Construction May 29, 2025
4 Gloucester County Virginia www.gloucesterva.gov 🇺🇸 United States Public Sector May 15, 2025
5 Pacific Metallurgical www.pacmet.com 🇺🇸 United States Manufacturing Apr 24, 2025
6 The Fortune Society fortunesociety.org 🇺🇸 United States Public Sector Apr 24, 2025
7 Massachusetts Municipal Wholesale Electric mmwec.org 🇺🇸 United States Energy Apr 4, 2025
8 dapope.com dapope.com 🇺🇸 United States Mar 29, 2025
9 Town of Orangeville orangeville.ca 🇨🇦 Canada Public Sector Mar 29, 2025
10 midwest.com midwest.com 🇺🇸 United States Business Services Dec 11, 2024
11 copresi.es copresi.es 🇪🇸 Spain Dec 9, 2024
12 JTEKT NORTH AMERICA jtekt-na.com 🇺🇸 United States Manufacturing Nov 29, 2024
13 Grandview School District gsd200.org 🇺🇸 United States Education Nov 27, 2024
14 co.cullman.al.us co.cullman.al.us 🇺🇸 United States Public Sector Nov 24, 2024
15 eastgateauto.com eastgateauto.com 🇺🇸 United States Transportation/Logistics Nov 18, 2024
16 kciaviation.com kciaviation.com 🇺🇸 United States Transportation/Logistics Nov 18, 2024
17 hetrhedens.nl hetrhedens.nl 🇳🇱 Netherlands Education Nov 17, 2024
18 brandywinecoachworks.com brandywinecoachworks.com 🇺🇸 United States Transportation/Logistics Nov 16, 2024
19 kapurinc.com kapurinc.com 🇮🇳 India Business Services Nov 16, 2024
20 billyheromans.com billyheromans.com 🇺🇸 United States Business Services Nov 15, 2024
21 kenmore.com kenmore.com 🇺🇸 United States Business Services Nov 15, 2024
22 klarenbeek-transport.nl klarenbeek-transport.nl 🇳🇱 Netherlands Transportation/Logistics Nov 15, 2024
23 marysville.k12.oh.us marysville.k12.oh.us 🇺🇸 United States Education Nov 15, 2024
24 surgicalassociates.com surgicalassociates.com 🇺🇸 United States Healthcare Nov 15, 2024
25 stalyhill-inf.tameside.sch.uk stalyhill-inf.tameside.sch.uk 🇬🇧 United Kingdom Education Nov 13, 2024
26 jarrellimc.com jarrellinc.com 🇺🇸 United States Business Services Nov 12, 2024
27 jst.es jst.es 🇪🇸 Spain Technology Nov 12, 2024
28 steppingstonesd.org steppingstonesd.org 🇺🇸 United States Education Nov 12, 2024
29 dezinecorp.com dezinecorp.com 🇨🇦 Canada Business Services Nov 11, 2024
30 Maxxis International maxxis.com 🇻🇳 Vietnam Manufacturing Nov 11, 2024
31 Supply Technologies supplytechnologies.com 🇺🇸 United States Transportation/Logistics Nov 11, 2024
32 SVP Worldwide svpworldwide.com 🇺🇸 United States Business Services Nov 2, 2024
33 nathcompanies.com nathcompanies.com 🇺🇸 United States Hospitality and Tourism Oct 29, 2024
34 wescan-services.com 760 GB wescan-services.com 🇨🇭 Switzerland Business Services Oct 26, 2024
35 wescan-services.com wescan-services.com LU Business Services Oct 26, 2024
36 deschampsimp.com deschampsimp.com 🇨🇦 Canada Manufacturing Oct 25, 2024
37 lolaliza.com lolaliza.com 🇧🇪 Belgium Business Services Oct 25, 2024
38 nrcs.net nrcs.net 🇨🇭 Switzerland Technology Oct 25, 2024
39 omara-ag.com omara-ag.com 🇩🇪 Germany Agriculture and Food Production Oct 25, 2024
40 unitedsprinkler.com unitedsprinkler.com 🇺🇸 United States Business Services Oct 25, 2024
41 zyloware.com zyloware.com 🇺🇸 United States Business Services Oct 25, 2024
42 Aerotecnic aerotecnic.com 🇪🇸 Spain Manufacturing Oct 22, 2024
43 Teddy SpA teddy.it 🇮🇹 Italy Business Services Oct 21, 2024
44 Kansas City Hospice kchospice.org 🇺🇸 United States Healthcare Oct 19, 2024
45 mopsohio.com mopsohio.com 🇺🇸 United States Transportation/Logistics Oct 19, 2024
46 rcschools.net rcschools.net 🇺🇸 United States Education Oct 19, 2024
47 Neighbors Credit Union neighborscu.org 🇺🇸 United States Financial Services Oct 18, 2024
48 Volta River Authority vra.com GH Energy Oct 11, 2024
49 GenPro Inc. genproinc.com 🇺🇸 United States Transportation/Logistics Oct 4, 2024
50 Branhaven Chrysler Dodge Jeep Ram branhaven.com 🇺🇸 United States Business Services Oct 2, 2024
51 decalesp.com decalesp.com 🇪🇸 Spain Business Services Sep 30, 2024
52 lolaliza.com - 250kk lolaliza.com 🇧🇪 Belgium Business Services Sep 26, 2024
53 cottlesinc.com cottlesinc.com 🇺🇸 United States Manufacturing Sep 24, 2024
54 Menninger Clinic menningerclinic.org 🇺🇸 United States Healthcare Sep 24, 2024
55 FD Lawrence Electric fdlawrence.com 🇺🇸 United States Energy Sep 13, 2024
56 Hostetler Buildings hostetlergroup.com 🇺🇸 United States Business Services Sep 13, 2024
57 Charles Darwin School cdarwin.com 🇬🇧 United Kingdom Education Sep 11, 2024
58 Kadokawa Co Jp kadokawa.co.jp 🇯🇵 Japan Technology Sep 10, 2024
59 OSDA Contract Services osda.com 🇬🇧 United Kingdom Business Services Sep 4, 2024
60 Parrish parrishandcompany.com 🇺🇸 United States Healthcare Sep 4, 2024
61 Effortless Office effortlessoffice.com 🇺🇸 United States Technology Aug 31, 2024
62 Goodless Dermatology goodlessdermatology.com 🇺🇸 United States Healthcare Aug 31, 2024
63 MorningStar Senior Living morningstarseniorliving.com 🇺🇸 United States Healthcare Aug 31, 2024
64 Nevada Heart Vascular Center nevadaheart.com 🇺🇸 United States Healthcare Aug 31, 2024
65 Southwest Traders southwesttraders.com 🇺🇸 United States Transportation/Logistics Aug 31, 2024
66 Clatronic International GmbH clatronic.com 🇩🇪 Germany Business Services Aug 29, 2024
67 Hollywood Burbank Airport hollywoodburbankairport.com 🇺🇸 United States Transportation/Logistics Aug 29, 2024
68 malonetoyota.com malonetoyota.com 🇺🇸 United States Business Services Aug 29, 2024
69 Academy of Model Aeronautics modelaircraft.org 🇺🇸 United States Business Services Aug 27, 2024
70 widex.com widex.com 🇩🇰 Denmark Healthcare Aug 26, 2024
71 nwcsb.com nwcsb.com 🇺🇸 United States Healthcare Aug 24, 2024
72 Bandier wearesbi.com 🇺🇸 United States Business Services Aug 19, 2024
73 Forrec forrec.it 🇮🇹 Italy Business Services Aug 13, 2024
74 aikenhousing.org aikenhousing.org/ 🇺🇸 United States Public Sector Aug 3, 2024
75 Bettis Asphalt bettisasphalt.com 🇺🇸 United States Business Services Aug 3, 2024
76 acsi.org acsi.org/ 🇺🇸 United States Public Sector Aug 1, 2024
77 www.chsd117.org chsd117.org 🇺🇸 United States Education Jul 30, 2024
78 hanoverhill.com hanoverhill.com 🇺🇸 United States Jul 27, 2024
79 Pojoaque pojoaque.org 🇺🇸 United States Public Sector Jul 25, 2024
80 RhinoCorps rhinocorps.com 🇺🇸 United States Jul 24, 2024
81 Reward Hospitality from EFC Group ecfgroup.com/en/brand/reward-hospitality/;https://www.rewardhospitality.com.au/ 🇦🇺 Australia Hospitality and Tourism Jul 20, 2024
82 a-g.com - data publication 38gb (150K) a-g.com 🇺🇸 United States Agriculture and Food Production Jul 13, 2024
83 gbhs.org 07/12 Publication 51gb gbhs.org/ Healthcare Jul 13, 2024
84 gbhs.org Publication 51gb gbhs.org/ Healthcare Jul 13, 2024
85 Image Microsystems dealscoop.com Technology Jul 11, 2024
86 City of Cedar Falls cedarfalls.com Public Sector Jul 10, 2024
87 a-g.com 7/10/24 - data publication 38gb (150K) a-g.com 🇺🇸 United States Business Services Jul 6, 2024
88 National Health Laboratory Services nhls.ac.za 🇿🇦 South Africa Healthcare Jul 5, 2024
89 KADOKAWA Corporation kadokawa.co.jp 🇯🇵 Japan Consumer Services Jun 27, 2024
90 arangobillboard.com arangobillboard.com 🇺🇸 United States Business Services Jun 25, 2024
91 axiavg.com axiavg.com 🇮🇹 Italy Technology Jun 25, 2024
92 catiglass.com catiglass.com 🇺🇸 United States Manufacturing Jun 25, 2024
93 doityoungs.com doityoungs.com 🇬🇧 United Kingdom Construction Jun 25, 2024
94 ibewlocal1.org ibewlocal1.org 🇺🇸 United States Business Services Jun 25, 2024
95 keeservices.com keeservices.com 🇬🇧 United Kingdom Business Services Jun 25, 2024
96 peregrinegp.com (178gb + private SQL_DB 24gb) peregrinegp.com 🇺🇸 United States Technology Jun 25, 2024
97 rbbschools.net rbbschools.net/ 🇺🇸 United States Education Jun 25, 2024
98 sanglier.org.uk sanglier.org.uk 🇬🇧 United Kingdom Business Services Jun 25, 2024
99 theeyeclinicsurgicenter.com theeyeclinicsurgicenter.com 🇺🇸 United States Healthcare Jun 25, 2024
100 hiawathahomes.org hiawathahomes.org 🇺🇸 United States Healthcare Jun 24, 2024

Frequently Asked Questions

What is Blacksuit ransomware?

Blacksuit is a ransomware threat group that has claimed 165 victims since its first known activity in January 2024. The group operates by infiltrating target networks, exfiltrating data, encrypting files, and threatening to publish stolen data on a dark web leak site if the ransom is not paid.

How many victims has Blacksuit attacked?

Blacksuit has claimed 165 victims in our database, representing 0.8% of all tracked ransomware attacks. The most targeted countries are United States, United Kingdom, Canada, Spain.

Which countries does Blacksuit target?

Blacksuit has attacked organizations in 20 countries. The top targeted countries are: United States, United Kingdom, Canada, Spain.

Which industries does Blacksuit target?

Blacksuit most frequently targets the Business Services, Healthcare, Manufacturing sectors based on victim disclosures in our database.

Is Blacksuit still active?

Blacksuit's most recent victim disclosure in our database was on June 2, 2025. Ransomware groups frequently rebrand or go dormant; monitor this page and our ransomware map for the latest activity.