BlackSuit
Threat Actor
BlackSuit emerged in May 2023 and mainly targets US companies in the education and industrial goods sectors. BlackSuit uses a double-extortion method and other tactics, techniques, and procedures (TTPs) that reflect a maturity atypical of a group that's only been around for a year. This reflects its origin in Royal, which in turn was comprised of members of the formidable and now-defunct Conti ransomware gang.
Incidents Associated with this Threat
- January 25, 2025: Cyberattack at MA Utility
- June 19, 2024: BlackSuit Ransomware Attack at CDK Global Causes Widespread Disruption
- June 13, 2024: Ransomware Attack at Dutch Eurotrol B.V.
- June 8, 2024: Cyberattack Impacted Kadokawa’s and its Subsidiary’s Operations.
- April 15, 2024: Plasma Donation Company Octapharma Shuts Down 180 Centers Worldwide
Malware Used by this Threat Actor
No malware identified for this threat actor.
