TF-MAL-elf.blacksuit
📛 Threat Title
Malware family: BlackSuit
Description
ThreatFox malware family `elf.blacksuit`. Printable name: BlackSuit.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.blacksuit
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.blacksuit
IOC database
- Type
- domain
- Value
elf.blacksuit- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.blacksuit
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.blacksuit
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:dailysecurityreview.com
BlackSuit , formerly Royal, is a sophisticated ransomware group using multi-vector attacks, partial encryption, and double extortion to target global organizations, including critical infrastructure. Their operations are suspected to involve former Conti members.
-
web:fidelissecurity.com
BlackSuit ransomware is a type of malware variant designed to encrypt victim system files, rendering critical data breach. The attackers then demand a ransom in exchange for the decryption key, while some threat actors deploy a double extortion model, with ransomware threats of releasing the stolen data to the public if their demands are not met. The ransomware targets mainly critical sectors ...
-
web:fticybersecurity.com
BlackSuit ransomware payloads are known to affect both Windows and Linux operating systems. The group has successfully used a variety of initial access vectors to access organizational networks before deploying ransomware, including phishing emails, malicious torrent files, third-party tools, malicious ads, trojans, and stolen Virtual Private Network (VPN) credentials .
-
web:github.com
A ransomware attack was detected in an organization, and forensic investigation revealed a suspicious executable executed on multiple endpoints before files were encrypted. The Incident Response (IR) team isolated the malware sample and provided it for in-depth analysis. Our goal is to analyze the ransomware, uncover its behavior, and identify weaknesses that could aid in recovery and future ...
-
web:industrialcyber.co
The FBI observed BlackSuit hackers using legitimate remote monitoring and management (RMM) software, to maintain persistence in victim networks. They also use SystemBC and Gootloader malware to load additional tools and maintain persistence. BlackSuit hackers have been observed using SharpShares and SoftPerfect NetWorx to enumerate victim networks.
-
web:malpedia.caad.fkie.fraunhofer.de
BlackSuit Attack Analysis BlackSuit 2023-05-31 ⋅ Trend Micro ⋅ Ieriz Nicolle Gonzalez, Ivan Nicole Chavez, Jeffrey Francis Bonaobra, Katherine Casona, Trend Micro Investigating BlackSuit Ransomware's Similarities to Royal BlackSuit BlackSuit 2023-05-12 ⋅ cyble ⋅ Cyble BlackSuit Ransomware Strikes Windows and Linux Users BlackSuit ...
-
web:www.cisa.gov
BlackSuit ransomware is the evolution of the ransomware previously identified as Royal ransomware, which was used from approximately September 2022 through June 2023. BlackSuit shares numerous coding similarities with Royal ransomware and has exhibited improved capabilities.
-
web:www.hhs.gov
Overview BlackSuit operates using a double extortion method that steals and encrypts sensitive data on a compromised network. So far, the specific use of BlackSuit ransomware has been observed in a small number of attacks. The most recent suspected attack, in October 2023, was against a U.S.-based HPH organization whose servers and systems were encrypted with malware , tentatively identified as ...
-
web:www.huntress.com
What is BlackSuit Malware ? BlackSuit is a sophisticated ransomware strain designed to encrypt files and demand payment for decryption. Known for targeting businesses and critical infrastructure, it employs advanced evasion techniques to bypass traditional defenses.
-
web:www.sentinelone.com
BlackSuit Ransomware FAQs What is BlackSuit ransomware? BlackSuit is a ransomware strain that emerged in May 2023. It's merely a new name given to the Royal ransomware family . BlackSuit ransomware attacks by encrypting your files—but they use double extortion and steal your files before encrypting them.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.