Last seven days
- First activity
- Jul 20, 2026
- Last activity
- Jul 20, 2026
- Feed role
- C2 / Distribution
- Host form
- 8 IP / 6 hostnames
BlackMatter is a ransomware-as-a-service (RaaS) operation that emerged in late July 2021 after the apparent shutdown of DarkSide and REvil.
Profile source: Mallory opens in a new tabBLACKMATTER
BlackMatter is a ransomware-as-a-service (RaaS) operation that emerged in late July 2021 after the apparent shutdown of DarkSide and REvil. Multiple sources link it to the former DarkSide ecosystem: Microsoft states ELBRUS/FIN7 released BlackMatter in July 2021 as DarkSide’s successor and retired it in November 2021, while Sophos assessed BlackMatter shows multiple technical connections to DarkSide but is not simply identical code or a direct rebrand. BlackMatter has also been discussed in reporting about later ransomware lineages, including overlaps with LockBit 3.0/LockBit Black and ALPHV/BlackCat, and ExMatter is identified as BlackMatter’s custom data-exfiltration tool.
BlackMatter is a double-extortion ransomware family. Reported campaigns involved both file encryption and exfiltration of victim data, with ransom demands backed by threats to delete or publicly expose stolen information. Splunk content states BlackMatter campaigns targeted healthcare and other vertical sectors, citing an HHS bulletin. BlackMatter has also been listed among ransomware families observed targeting VMware ESXi environments.
Technically, BlackMatter uses in-place, multithreaded, partial file encryption and renames files before encryption. Sophos reported that it appends a decryption blob to the end of encrypted files, sets a ransom wallpaper very similar to DarkSide’s, uses runtime API resolution and runtime string decryption, and changes file DACLs to grant Everyone full access before encryption. The analyzed sample collected victim host details and sent them to a remote server hosted on paymenthacks.com. BlackMatter supports Safe Mode encryption via the -safe switch and can enable the built-in local Administrator account, configure AutoAdminLogon, set RunOnce registry entries, and use bcdedit to reboot into Safe Mode with Networking before encrypting files; afterward it removes the safeboot setting and restarts the machine. It also uses the elevated COM object Elevation:Administrator!new:{3E5FC7F9-9A51-4367-9063-A120244FBEC7} for UAC bypass. Splunk detections and attack simulations further associate BlackMatter with AutoAdminLogon registry modification, DefaultUserName/DefaultPassword registry additions under Winlogon, bcdedit-based Safe Mode boot changes, return-to-normal boot changes, wallpaper modification, stopping security and backup services, and schcache access caused by creation of an ADSI object for an LDAP query.
Observed deployment tradecraft includes execution via a scheduled task that runs a PowerShell script from a domain-accessible UNC path, with the ransomware binary base64-encoded inside the script. Cisco Talos compared a September 2021 BlackMatter intrusion with a later BlackCat intrusion and found BlackMatter operators using GOST for reverse SSH tunneling, scheduled tasks for persistence, LSASS dumping via comsvcs.dll minidump through rundll32, lateral movement via Impacket wmiexec, WinRM/PowerShell, RDP, and PsExec/RemCom, firewall changes to permit inbound TCP 5985, Group Policy-based domain-wide deployment using apply.ps1 and gpupdate /force, and execution of ransomware binaries from the domain controller’s NETLOGON share. Talos also noted a BlackMatter attack may have involved exploitation of Microsoft Exchange vulnerabilities, though with low confidence.
BlackMatter is associated in the provided content with ELBRUS/FIN7 and the post-DarkSide ransomware ecosystem. Reporting also notes likely connections between RAMP forum members and BlackMatter, and later reporting on ALPHV/BlackCat describes overlaps with the now-defunct BlackMatter family. High-confidence indicators directly mentioned in the content include the Sophos-analyzed sample SHA-256 22D7D67C3AF10B1A37F277EBABE2D1EB4FD25AFBD6437D4377400E148BCC08D6, the paymenthacks.com server used by that sample for host-information transmission, and Talos infrastructure including the domain windows[.]menu and IPs 52.149.228[.]45 and 20.46.245[.]56 observed in related intrusion activity.
C2 tracking
Derp observations, rolling seven-day window
Samples
2fcad226b17131da4274e1b9f8f31359bdd325c9568665f08fd1f6c5d06a23ce 27c2134b7774f29e657f881ca9177fe6e93a9b6e03fda4579168b9099c0005a8 4e5cc8cb98584335400d00f0a0803c3e0202761f3fbe50bcab3858a80df255e1 4e5cebe1908e12e8a4ed1198fb01fb87871dbe54847855b11b3540dbc47bbe88 5bcc428f37655c7bc16110cc2127c510f66827a382cb1c9fa251b15a7d2c214b 65ba3988d38f83b9ee1f31cafa5bd37dc6b72279f5618aac94d71a904efa0cac 9cd9c0a79450290b1ac0ea3235df6cd68332cc5a426991fa1d53eb7f19ec5a09 ecda70414eaa3354ef877c71c445d49294f142fc694e81f0002d385ff1060d02 1ebf64ceb8ec5601ead8cd44c4a3b22a7e9b5a8a4432ea70e96e2837495b19a9 526abca3f813871d7e2930c99bbe9c1d6a660cb7e6624e65e54154e4e3cf897d Reported operators
In 2023, FIN7 expanded its operations to include the deployment of ransomware through affiliations with RaaS groups such as REvil and Maze, while also managing its own RaaS programs, including the now-retired Darkside and BlackMatter.
ELBRUS retired the DarkSide ransomware ecosystem in May 2021 and released its successor, BlackMatter, in July 2021.
MITRE ATT&CK
Reporting
GG recommended looking into Darkside/Blackmatter/BlackCat ESXi locker(s), praising its quality and admin panel.
This activity is significant because it is a known technique used by BlackMatter ransomware to force a compromised host into safe mode for continued encryption.
Associated Analytic Story BlackMatter Ransomware
This activity is significant as it may indicate the presence of ransomware, such as BlackMatter, which manipulates boot configurations to facilitate encryption processes.
This activity is significant because it was observed in BlackMatter ransomware attacks to maintain access after a safe mode reboot, facilitating further encryption.
This activity is significant because it is associated with BlackMatter ransomware, which uses this technique to automatically log on to compromised hosts and continue encryption after a safe mode boot.
Associated Analytic Story BlackMatter Ransomware
In 2023, FIN7 expanded its operations to include the deployment of ransomware through affiliations with RaaS groups such as REvil and Maze, while also managing its own RaaS programs, including the now-retired Darkside and BlackMatter.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.