s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.blacksuit

📛 Threat Title

Malware family: BlackSuit

Category: BlackSuit First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.blacksuit`. Printable name: BlackSuit.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.blacksuit VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.blacksuit

IOC database

Type
domain
Value
elf.blacksuit
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.blacksuit

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.blacksuit

References (1)

Remediations (10)

  • web:dailysecurityreview.com

    BlackSuit , formerly Royal, is a sophisticated ransomware group using multi-vector attacks, partial encryption, and double extortion to target global organizations, including critical infrastructure. Their operations are suspected to involve former Conti members.

  • web:fidelissecurity.com

    BlackSuit ransomware is a type of malware variant designed to encrypt victim system files, rendering critical data breach. The attackers then demand a ransom in exchange for the decryption key, while some threat actors deploy a double extortion model, with ransomware threats of releasing the stolen data to the public if their demands are not met. The ransomware targets mainly critical sectors ...

  • web:fticybersecurity.com

    BlackSuit ransomware payloads are known to affect both Windows and Linux operating systems. The group has successfully used a variety of initial access vectors to access organizational networks before deploying ransomware, including phishing emails, malicious torrent files, third-party tools, malicious ads, trojans, and stolen Virtual Private Network (VPN) credentials .

  • web:github.com

    A ransomware attack was detected in an organization, and forensic investigation revealed a suspicious executable executed on multiple endpoints before files were encrypted. The Incident Response (IR) team isolated the malware sample and provided it for in-depth analysis. Our goal is to analyze the ransomware, uncover its behavior, and identify weaknesses that could aid in recovery and future ...

  • web:industrialcyber.co

    The FBI observed BlackSuit hackers using legitimate remote monitoring and management (RMM) software, to maintain persistence in victim networks. They also use SystemBC and Gootloader malware to load additional tools and maintain persistence. BlackSuit hackers have been observed using SharpShares and SoftPerfect NetWorx to enumerate victim networks.

  • web:malpedia.caad.fkie.fraunhofer.de

    BlackSuit Attack Analysis BlackSuit 2023-05-31 ⋅ Trend Micro ⋅ Ieriz Nicolle Gonzalez, Ivan Nicole Chavez, Jeffrey Francis Bonaobra, Katherine Casona, Trend Micro Investigating BlackSuit Ransomware's Similarities to Royal BlackSuit BlackSuit 2023-05-12 ⋅ cyble ⋅ Cyble BlackSuit Ransomware Strikes Windows and Linux Users BlackSuit ...

  • web:www.cisa.gov

    BlackSuit ransomware is the evolution of the ransomware previously identified as Royal ransomware, which was used from approximately September 2022 through June 2023. BlackSuit shares numerous coding similarities with Royal ransomware and has exhibited improved capabilities.

  • web:www.hhs.gov

    Overview BlackSuit operates using a double extortion method that steals and encrypts sensitive data on a compromised network. So far, the specific use of BlackSuit ransomware has been observed in a small number of attacks. The most recent suspected attack, in October 2023, was against a U.S.-based HPH organization whose servers and systems were encrypted with malware , tentatively identified as ...

  • web:www.huntress.com

    What is BlackSuit Malware ? BlackSuit is a sophisticated ransomware strain designed to encrypt files and demand payment for decryption. Known for targeting businesses and critical infrastructure, it employs advanced evasion techniques to bypass traditional defenses.

  • web:www.sentinelone.com

    BlackSuit Ransomware FAQs What is BlackSuit ransomware? BlackSuit is a ransomware strain that emerged in May 2023. It's merely a new name given to the Royal ransomware family . BlackSuit ransomware attacks by encrypting your files—but they use double extortion and steal your files before encrypting them.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.