Credential Theft
- AccountRestore
- Mimikatz
- NirSoft Dialupass
- NirSoft IEPassView (iepv)
- NirSoft MailPassView
- NirSoft Netpass
- NirSoft RouterPassView
BlackSuit is a Windows ransomware family and extortion operation closely associated with Royal and widely assessed as part of the broader Conti-derived ransomware ecosystem.
Profile source: Mallory opens in a new tabBlackSuit
BlackSuit is a Windows ransomware family and extortion operation closely associated with Royal and widely assessed as part of the broader Conti-derived ransomware ecosystem. It emerged as a distinct encryptor used by operators linked to Royal, with strong technical overlap reported between the two, including similar code structure, command-line options, file exclusions, and intermittent encryption behavior. BlackSuit has been described both as a Royal rebrand candidate and as a parallel locker used by the same or closely related operators.
BlackSuit intrusions are associated with enterprise-targeting ransomware tradecraft focused on rapid expansion after initial access. Reported activity tied to the Royal/BlackSuit lineage includes spearphishing campaigns that delivered Qbot on Windows systems, followed by use of PowerShell, Cobalt Strike, stolen credentials, remote administrative shares, and legitimate Windows utilities to gain privileged domain access and move laterally. Other reporting links operators in this lineage to social-engineering-based initial access, including impersonation of IT support over Microsoft Teams and voice calls to persuade users to launch remote assistance tools. Across ransomware investigations, Royal and BlackSuit have also been associated with common post-compromise tooling such as PsExec for lateral movement and NirSoft utilities for credential theft.
The malware is used in financially motivated double-extortion operations. Operators have been observed exfiltrating data to cloud storage services before encryption, then deploying ransomware broadly across compromised Windows environments. BlackSuit activity has also been linked to attack chains in which endpoint defenses are first disabled using specialized EDR-killer tooling before ransomware execution. The broader ecosystem around BlackSuit has included abuse-resistant hosting providers and criminal support services used for infrastructure, command-and-control, and extortion operations.
Victimology is consistent with big-game hunting ransomware. Reporting has tied BlackSuit-related activity to attacks against organizations across sectors including healthcare, government, telecommunications, finance, education, manufacturing, energy, construction, and other enterprise environments, with notable concentration in North America in some observed campaigns. BlackSuit is best understood as a Conti-lineage ransomware brand operating in close relationship with Royal, using mature intrusion tradecraft, credential theft, lateral movement, data exfiltration, and defense evasion to turn initial compromise into enterprise-wide encryption and extortion.
104.244.75.168Reported operators
Rapid7 disclosed that the initial infiltration strategy used by BlackBasta after the February 2025 internal chat leak was identified in the BlackSuit ransomware group: email bombing followed by impersonating helpdesk staff and contacting them via Microsoft Teams and voice calls to trick them into installing remote access tools such as Quick Assist, AnyDesk, and ScreenConnect.
A threat actor group that Microsoft designated as DEV-0569 (now Storm-0569) used a very similar technique in late 2022 to deploy Royal ransomware.
A threat actor group that Microsoft designated as DEV-0569 (now Storm-0569) used a very similar technique in late 2022 to deploy Royal ransomware.
"Royal ransomware is following in the same path, a new variant targeting Linux systems emerged... Royal’s Linux counterpart also targets ESXi servers"; "In its early campaigns, Royal deployed BlackCat’s encryptor, but later shifted to its own called Zeon".
...BlackSuite Ransomware Gang...
“…BlackSuit ransomware actors breached CDK Global… strongly suggesting it is rebranding of Royal ransomware.”
...Stern has transacted with addresses linked to strains like Quantum, Karakurt, Diavol, and Royal in 2022 following Conti’s demise.
MITRE ATT&CK
Reporting
The U.S. Treasury sanctioned First VPN Service (1VPNS), its alleged Ukrainian administrator Dmytro Rashevskyi, and Belarusian cryptor seller Yevgeniy Vladimirovich Silayev for allegedly supporting ransomware and other cybercriminal activity. Officials said 1VPNS provided anonymizing infrastructure that helped threat actors hide their identities, disguise malware, and evade detection during attacks on U.S. municipalities, hospitals, schools, businesses, and critical infrastructure providers. Treasury alleged Rashevskyi used false identities to obtain infrastructure for the service, while Silayev sold malware-obfuscation tools that made malicious code harder for defenders to detect. The sanctions, issued under Executive Order 14390 and E.O. 13694 as amended, block U.S. persons from transacting with the designated parties and mark a broader move against ransomware enablers rather than only the gangs themselves. The action was coordinated with the United Kingdom and followed a May law enforcement takedown of 1VPNS infrastructure by European agencies with FBI support. Separate reporting said blockchain tracing tied payments from ransomware groups including Anubis, Qilin, and Sinobi Group to FirstVPN, adding financial evidence that the service was used as operational infrastructure by ransomware actors.
Attackers compromised the Artlist WordPress subdomain new-blog.artlist[.]io and used it to deliver a sophisticated ClickFix malware campaign that presented visitors with a fake CAPTCHA and tricked them into running PowerShell. The injected JavaScript used an EtherHiding technique, querying a Polygon smart contract to dynamically retrieve the next-stage host auth-code-check[.]info, then downloaded a multi-stage infection chain from the attacker-controlled backend. Researchers traced the intrusion to WordPress credentials stolen from an Israeli freelance developer whose machine had been infected by an infostealer after downloading a pirated copy of Adobe Acrobat Pro DC in 2023. The payload chain reportedly used a password-protected archive, a signed StruSoft/FEM-Design updater, and DLL side-loading to decode shellcode and load a final native RAT that supported encrypted and Tor-backed C2, browser credential theft, keylogging, clipboard and screen access, hidden desktop interaction, file transfer, shell and process control, SOCKS proxying, service installation, and in-memory PE delivery.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.