Exfiltration
- PrivatLab
BlackMatter is a ransomware-as-a-service operation that emerged in July 2021 and is widely assessed as a successor or rebrand of DarkSide, with code, operational, and personnel overlap also noted with REvil.
Profile source: Mallory opens in a new tabBLACKMATTER
BlackMatter is a ransomware-as-a-service operation that emerged in July 2021 and is widely assessed as a successor or rebrand of DarkSide, with code, operational, and personnel overlap also noted with REvil. It conducted big-game hunting extortion against large organizations, especially enterprises with annual revenue above $100 million, and was active until November 2021. Victims included organizations in critical infrastructure sectors despite the group’s public claims that some sectors were off-limits.
BlackMatter primarily targeted Windows environments and also fielded Linux tooling. Windows payloads were custom-configurable per victim and designed for efficient multithreaded encryption, privilege escalation, and anti-analysis. Reported behaviors include use of a COM-based UAC bypass, process and service enumeration, deletion of shadow copies, Active Directory and network-share discovery via LDAP, SMB, and administrative share enumeration, and remote encryption of accessible shares from the initially compromised host. The malware used partial encryption to accelerate impact and employed native Windows cryptographic functionality. BlackMatter also attempted data exfiltration as part of double-extortion operations and used a dedicated exfiltration utility known as Fendr or ExMatter.
Linux-associated BlackMatter tooling has been described in two ways in reporting: as a Linux encryptor, including variants aimed at VMware ESXi environments, and in some government reporting as Linux payloads functioning as remote access trojans used to pivot toward Windows systems rather than encrypt Linux data. High-confidence reporting supports that BlackMatter had Linux-targeting capability and targeted ESXi environments.
Initial access was commonly obtained through exploitation of vulnerable internet-facing infrastructure, including remote access and virtualization appliances, and through compromised credentials. The operation also recruited access brokers and insiders to provide footholds into enterprise networks. Once inside, affiliates used legitimate administrative tools and remote management software for persistence and lateral movement, harvested credentials, and deployed ransomware across domain environments and shared resources.
BlackMatter is notable for its short but consequential lifespan, its close lineage with DarkSide, and its role in the evolution of later ransomware ecosystems. Multiple later families, including BlackCat/ALPHV and LockBit variants, have been reported to share code, configuration, tooling, or tradecraft similarities with BlackMatter.
Reported operators
À Darkside succède le RaaS BlackMatter, qui disparaît à son tour en novembre 2021.
BlackMatter Ransomware ... Этот крипто-вымогатель шифрует данные бизнес-пользователей с помощью Salsa20 + RSA-1024, а затем требует выкуп в BTC или XMR (Monero) ... BlackMatter был представлен на форумах кибер-андеграунда 21 июля 2021.
At least one affiliate of the BlackMatter ransomware operation has begun using a custom data exfiltration tool in its attacks.
ELBRUS retired the DarkSide ransomware ecosystem in May 2021 and released its successor, BlackMatter, in July 2021.
MITRE ATT&CK
Reporting
Security researchers detailed BPFDoor, a stealthy Linux backdoor attributed by PwC to the China-linked group Red Menshen, describing its use in long-running intrusions against telecommunications, government, logistics, and education organizations in the Middle East and Asia. The malware is designed for covert re-entry and persistence, using raw sockets and Berkeley Packet Filter (BPF) logic to inspect network traffic for specially crafted magic packets, then launching a reverse shell, bind shell, or pingback without exposing obvious new listening services. Researchers said BPFDoor can hide behind legitimate network activity by listening on traffic destined for existing services such as 443, allowing operators to execute commands while avoiding conspicuous firewall or port changes. Analysis showed the malware often copies itself into /dev/shm, deletes the original binary, spoofs process names, creates PID files under /var/run, and can temporarily alter iptables to hijack traffic for command and control; historical samples appeared functionally stable over time, with changes largely limited to hardcoded passwords, filenames, and process names. Elastic and other researchers published hunting guidance, YARA signatures, and tooling to help defenders identify infections.
Trend Micro reported that the Kasseika ransomware used a bring-your-own-vulnerable-driver (BYOVD) technique to compromise Windows environments, disable security tools, and encrypt victim files. In the investigated intrusion, the attackers reportedly gained initial access through targeted phishing, then used remote administration tools and PsExec for execution and lateral movement. The malware abused the signed but vulnerable Martini.sys driver from TG Soft’s VirIT Agent System to terminate antivirus and analysis processes, allowing the ransomware to run with reduced interference. The operation also employed anti-analysis checks, cleared Windows event logs, and deleted shadow copies before encrypting files with ChaCha20 and RSA through CryptoPP. After encryption, Kasseika dropped ransom notes and changed the victim’s desktop wallpaper. Researchers said the malware shares multiple code and behavioral traits with BlackMatter, including ransom note naming conventions and apparent source-code overlap, indicating the operators may have obtained or reused parts of BlackMatter’s codebase.
Ranzy Locker emerged as a ransomware-as-a-service operation and a rebranded successor to ThunderX, with some code and infrastructure overlap also linked to Ako. Researchers reported that the group adopted double extortion, stealing data before encrypting systems and threatening to publish it on the "Ranzy Leak" site if victims refused to pay. The malware used Salsa20 file encryption with RSA-2048-protected keys, appended extensions such as .ranzy and .RNZ, and directed victims to ransom notes and a Tor-based payment and support portal. Reporting tied Ranzy intrusions to phishing, exploitation of Microsoft Exchange, and abuse of RDP valid accounts and brute-force access. Once inside a network, the malware enumerated local and network drives, discovered shares, accessed credentials, deleted backups and shadow copies, and disabled recovery options to increase pressure on victims. An FBI flash report cited in one analysis said the gang had compromised more than 30 U.S. businesses across multiple sectors by July 2021, and researchers noted that no public decryptor was available at the time despite detailed mapping of the group's tactics to the MITRE ATT&CK framework.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.