From Royal to BlackSuit: How a Ransomware Rebrand Reshaped Them
· Published 27/01/2025 14:18 · Modified 27/01/2025 14:28
Essential information
- Published
- 27/01/2025 14:18
- Modified
- 27/01/2025 14:28
- Tags
- 2025-01-27 blacksuit ransomware royal
- Related entities
- 8 observables, 1 intrusion sets (apt), 19 techniques (mitre), 25 malware, 3 others
Description
This intelligence report analyzes the evolution of the Russian-speaking ransomware group Royal as it rebranded to BlackSuit. The transition involved a shift from prioritizing data exfiltration to focusing more on encryption. The group's journey from 2022 to 2025 is detailed, including their tactics, tools, and internal struggles. BlackSuit's toolkit is extensively examined, featuring both proprietary malware and commercial tools. The report highlights the group's sophisticated approach, including the development of custom Command and Control frameworks and the use of advanced stealers. The rebranding process revealed critical characteristics of the group and shaped their future campaigns.
Related entities
Vulnerabilities, IOCs, intrusion sets, MITRE techniques and other entities referenced in this report.
Observables (8)
88.119.175.12479.132.129.13785.239.54.21479.141.162.131[email protected][email protected]ab893e68e5c5555df464d483bc92f0c1a37c9d411015b91646fc2dbca578ab4fde9b3c01991e357a349083f0db6af3e782f15e981e2bf0a16ba618252585923a
Intrusion sets (APT) (1)
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 05:17 · Modified 21/12/2025 05:17
Techniques (MITRE) (19)
-
Network Share Discovery
-
Virtualization/Sandbox Evasion
-
Account Discovery
-
Data from Local System
-
Remote Services
-
Data Encrypted for Impact
-
System Network Configuration Discovery
-
Application Layer Protocol
-
Process Injection
-
Exploitation of Remote Services
-
Network Service Discovery
-
Access Token Manipulation
-
User Execution
-
Obfuscated Files or Information
-
Phishing
-
Exploit Public-Facing Application
-
Valid Accounts
-
OS Credential Dumping
-
Command and Scripting Interpreter
Malware (25)
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 10:19 · Modified 21/12/2025 10:19
-
FamilyPublished 05/11/2025 09:36 · Modified 05/11/2025 09:36
-
FamilyPublished 04/03/2025 15:14 · Modified 04/03/2025 15:14
-
FamilyPublished 04/03/2025 15:14 · Modified 04/03/2025 15:14
-
FamilyPublished 24/07/2025 11:30 · Modified 24/07/2025 11:30
-
FamilyPublished 30/09/2025 05:15 · Modified 30/09/2025 05:15
-
FamilyPublished 30/09/2025 05:15 · Modified 30/09/2025 05:15
-
FamilyPublished 05/06/2026 18:07 · Modified 05/06/2026 18:07
-
FamilyPublished 05/06/2026 18:07 · Modified 05/06/2026 18:07
-
FamilyPublished 01/04/2025 14:48 · Modified 01/04/2025 14:48
-
FamilyPublished 01/04/2025 14:48 · Modified 01/04/2025 14:48
-
FamilyPublished 01/04/2025 14:48 · Modified 01/04/2025 14:48
-
FamilyPublished 06/11/2025 14:16 · Modified 06/11/2025 14:16
-
FamilyPublished 06/11/2025 14:16 · Modified 06/11/2025 14:16
-
FamilyPublished 07/08/2025 18:57 · Modified 07/08/2025 18:57
-
FamilyPublished 12/06/2026 16:57 · Modified 12/06/2026 16:57
-
FamilyPublished 06/11/2025 14:16 · Modified 06/11/2025 14:16
-
FamilyPublished 07/05/2026 17:05 · Modified 07/05/2026 17:05
-
FamilyPublished 27/01/2025 14:18 · Modified 27/01/2025 14:18
-
FamilyPublished 11/04/2025 09:39 · Modified 11/04/2025 09:39
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 23:50 · Modified 21/12/2025 16:13
-
FamilyPublished 01/04/2025 14:48 · Modified 01/04/2025 14:48
-
FamilyPublished 06/05/2026 10:26 · Modified 06/05/2026 10:26
-
FamilyPublished 27/01/2025 14:18 · Modified 27/01/2025 14:18
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 19:39 · Modified 27/05/2026 21:40
Others (3)
- United States of America
- Technology
- Government