Skip to content

BLACKMATTER

BlackMatter is a ransomware-as-a-service operation that emerged in July 2021 and is widely assessed as a successor or rebrand of DarkSide, with code, operational, and personnel overlap also noted with REvil.

Profile source: Mallory opens in a new tab

BLACKMATTER

Family profile

BlackMatter is a ransomware-as-a-service operation that emerged in July 2021 and is widely assessed as a successor or rebrand of DarkSide, with code, operational, and personnel overlap also noted with REvil. It conducted big-game hunting extortion against large organizations, especially enterprises with annual revenue above $100 million, and was active until November 2021. Victims included organizations in critical infrastructure sectors despite the group’s public claims that some sectors were off-limits.

BlackMatter primarily targeted Windows environments and also fielded Linux tooling. Windows payloads were custom-configurable per victim and designed for efficient multithreaded encryption, privilege escalation, and anti-analysis. Reported behaviors include use of a COM-based UAC bypass, process and service enumeration, deletion of shadow copies, Active Directory and network-share discovery via LDAP, SMB, and administrative share enumeration, and remote encryption of accessible shares from the initially compromised host. The malware used partial encryption to accelerate impact and employed native Windows cryptographic functionality. BlackMatter also attempted data exfiltration as part of double-extortion operations and used a dedicated exfiltration utility known as Fendr or ExMatter.

Linux-associated BlackMatter tooling has been described in two ways in reporting: as a Linux encryptor, including variants aimed at VMware ESXi environments, and in some government reporting as Linux payloads functioning as remote access trojans used to pivot toward Windows systems rather than encrypt Linux data. High-confidence reporting supports that BlackMatter had Linux-targeting capability and targeted ESXi environments.

Initial access was commonly obtained through exploitation of vulnerable internet-facing infrastructure, including remote access and virtualization appliances, and through compromised credentials. The operation also recruited access brokers and insiders to provide footholds into enterprise networks. Once inside, affiliates used legitimate administrative tools and remote management software for persistence and lateral movement, harvested credentials, and deployed ransomware across domain environments and shared resources.

BlackMatter is notable for its short but consequential lifespan, its close lineage with DarkSide, and its role in the evolution of later ransomware ecosystems. Multiple later families, including BlackCat/ALPHV and LockBit variants, have been reported to share code, configuration, tooling, or tradecraft similarities with BlackMatter.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Lateral Movement
  • Persistence
  • Privilege Escalation
  • Reconnaissance

Operational record

1
YARA rules
1
Ransom notes
2
Negotiations
1
Leak sites
0 available

Exfiltration

  • PrivatLab

Reported operators

Threat actors

4 named in public reporting
FIN7

À Darkside succède le RaaS BlackMatter, qui disparaît à son tour en novembre 2021.

BlackMatter

BlackMatter Ransomware ... Этот крипто-вымогатель шифрует данные бизнес-пользователей с помощью Salsa20 + RSA-1024, а затем требует выкуп в BTC или XMR (Monero) ... BlackMatter был представлен на форумах кибер-андеграунда 21 июля 2021.

Coreid

At least one affiliate of the BlackMatter ransomware operation has begun using a custom data exfiltration tool in its attacks.

Velvet Tempest

ELBRUS retired the DarkSide ransomware ecosystem in May 2021 and released its successor, BlackMatter, in July 2021.

MITRE ATT&CK

BLACKMATTER in ATT&CK

75 distinct techniques

Techniques

75 techniques
T1486 Data Encrypted for Impact T1584 Compromise Infrastructure T1497 Virtualization/Sandbox Evasion T1573 Encrypted Channel T1562.001 Disable or Modify Tools T1620 Reflective Code Loading T1548.002 Bypass User Account Control T1027 Obfuscated Files or Information T1078 Valid Accounts T1135 Network Share Discovery T1489 Service Stop T1112 Modify Registry T1547.001 Registry Run Keys / Startup Folder T1622 Debugger Evasion T1497.001 System Checks T1055 Process Injection T1134.001 Token Impersonation/Theft T1490 Inhibit System Recovery T1027.009 Embedded Payloads T1110 Brute Force T1657 Financial Theft T1569.002 Service Execution T1082 System Information Discovery T1565 Data Manipulation T1071.001 Web Protocols T1071 Application Layer Protocol T1057 Process Discovery T1098 Account Manipulation T1491.001 Internal Defacement T1190 Exploit Public-Facing Application T1007 System Service Discovery T1036 Masquerading T1543.003 Windows Service T1041 Exfiltration Over C2 Channel T1021 Remote Services T1070.004 File Deletion T1083 File and Directory Discovery T1482 Domain Trust Discovery T1021.002 SMB/Windows Admin Shares T1033 System Owner/User Discovery T1567 Exfiltration Over Web Service T1566 Phishing T1087 Account Discovery T1133 External Remote Services T1484.001 Group Policy Modification T1018 Remote System Discovery T1566.001 Spearphishing Attachment T1134 Access Token Manipulation T1047 Windows Management Instrumentation T1562 Impair Defenses T1021.004 SSH T1529 System Shutdown/Reboot T1027.007 Dynamic API Resolution T1003.001 LSASS Memory T1136 Create Account T1561 Disk Wipe T1562.009 Safe Mode Boot T1053 Scheduled Task/Job T1074 Data Staged T1105 Ingress Tool Transfer T1140 Deobfuscate/Decode Files or Information T1132 Data Encoding T1059 Command and Scripting Interpreter T1218.003 CMSTP T1564 Hide Artifacts T1583 Acquire Infrastructure T1059.001 PowerShell T1543 Create or Modify System Process T1548 Abuse Elevation Control Mechanism T1087.002 Domain Account T1491 Defacement T1053.005 Scheduled Task/Job: Scheduled Task T1003 OS Credential Dumping T1021.001 Remote Services: Remote Desktop Protocol T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage

Reporting

Research mentioning BLACKMATTER

Jan 1
Sandfly Security

BPFDoor - An Evasive Linux Backdoor Technical Analysis

Security researchers detailed BPFDoor, a stealthy Linux backdoor attributed by PwC to the China-linked group Red Menshen, describing its use in long-running intrusions against telecommunications, government, logistics, and education organizations in the Middle East and Asia. The malware is designed for covert re-entry and persistence, using raw sockets and Berkeley Packet Filter (BPF) logic to inspect network traffic for specially crafted magic packets, then launching a reverse shell, bind shell, or pingback without exposing obvious new listening services. Researchers said BPFDoor can hide behind legitimate network activity by listening on traffic destined for existing services such as 443, allowing operators to execute commands while avoiding conspicuous firewall or port changes. Analysis showed the malware often copies itself into /dev/shm, deletes the original binary, spoofs process names, creates PID files under /var/run, and can temporarily alter iptables to hijack traffic for command and control; historical samples appeared functionally stable over time, with changes largely limited to hardcoded passwords, filenames, and process names. Elastic and other researchers published hunting guidance, YARA signatures, and tooling to help defenders identify infections.

Jun 2
Haxrob

BPFDoor - Part 2 - The Present

Jan 23
Trend Micro Research

Kasseika Ransomware Deploys BYOVD Attacks Abuses PsExec and Exploits Martini Driver | Trend Micro (US)

Trend Micro reported that the Kasseika ransomware used a bring-your-own-vulnerable-driver (BYOVD) technique to compromise Windows environments, disable security tools, and encrypt victim files. In the investigated intrusion, the attackers reportedly gained initial access through targeted phishing, then used remote administration tools and PsExec for execution and lateral movement. The malware abused the signed but vulnerable Martini.sys driver from TG Soft’s VirIT Agent System to terminate antivirus and analysis processes, allowing the ransomware to run with reduced interference. The operation also employed anti-analysis checks, cleared Windows event logs, and deleted shadow copies before encrypting files with ChaCha20 and RSA through CryptoPP. After encryption, Kasseika dropped ransom notes and changed the victim’s desktop wallpaper. Researchers said the malware shares multiple code and behavioral traits with BlackMatter, including ransom note naming conventions and apparent source-code overlap, indicating the operators may have obtained or reused parts of BlackMatter’s codebase.

May 11
Bleeping Computer

Stealthier version of Linux BPFDoor malware spotted in the wild

Jul 13
Elastic Security Labs

A peek behind the BPFDoor - Elastic Security Labs

May 8
Doublepulsar

BPFDoor - an active Chinese global surveillance tool | by Kevin Beaumont | DoublePulsar

Oct 28
Picus Security

A Detailed Walkthrough of Ranzy Locker Ransomware TTPs

Ranzy Locker emerged as a ransomware-as-a-service operation and a rebranded successor to ThunderX, with some code and infrastructure overlap also linked to Ako. Researchers reported that the group adopted double extortion, stealing data before encrypting systems and threatening to publish it on the "Ranzy Leak" site if victims refused to pay. The malware used Salsa20 file encryption with RSA-2048-protected keys, appended extensions such as .ranzy and .RNZ, and directed victims to ransom notes and a Tor-based payment and support portal. Reporting tied Ranzy intrusions to phishing, exploitation of Microsoft Exchange, and abuse of RDP valid accounts and brute-force access. Once inside a network, the malware enumerated local and network drives, discovered shares, accessed credentials, deleted backups and shadow copies, and disabled recovery options to increase pressure on victims. An FBI flash report cited in one analysis said the gang had compromised more than 30 U.S. businesses across multiple sectors by July 2021, and researchers noted that no public decryptor was available at the time despite detailed mapping of the group's tactics to the MITRE ATT&CK framework.

Sep 2
Sentinelone Labs Subdomain

Ranzy Ransomware | Better Encryption Among New Features of ThunderX Derivative - SentinelLabs

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.