216.73.217.22

From Royal to BlackSuit: How a Ransomware Rebrand Reshaped Them

· Published 27/01/2025 14:18 · Modified 27/01/2025 14:28

Export JSON

Essential information

Published
27/01/2025 14:18
Modified
27/01/2025 14:28
Tags
2025-01-27 blacksuit ransomware royal
Related entities
8 observables, 1 intrusion sets (apt), 19 techniques (mitre), 25 malware, 3 others

Description

This intelligence report analyzes the evolution of the Russian-speaking group as it rebranded to . The transition involved a shift from prioritizing data exfiltration to focusing more on encryption. The group's journey from 2022 to 2025 is detailed, including their tactics, tools, and internal struggles. 's toolkit is extensively examined, featuring both proprietary malware and commercial tools. The report highlights the group's sophisticated approach, including the development of custom Command and Control frameworks and the use of advanced stealers. The rebranding process revealed critical characteristics of the group and shaped their future campaigns.

External references