216.73.217.98

Threat Assessment: Distributors of BlackSuit Ransomware

· Published 20/11/2024 22:03 · Modified 21/11/2024 09:23

Export JSON

Essential information

Published
20/11/2024 22:03
Modified
21/11/2024 09:23
Tags
2024-11-20 blacksuit cobalt strike credential-theft data exfiltration extortion gootloader lateral movement mimikatz nanodump ransomware supply chain attack systembc
Related entities
2 observables, 1 intrusion sets (apt), 6 malware, 4 others

Description

Ignoble Scorpius, previously known as Royal , has rebranded as and increased its activity since March 2024. The group has targeted at least 93 victims globally, with a focus on the construction and manufacturing industries. Their initial ransom demands average 1.6% of the victim's annual revenue. The group uses various initial access methods, including phishing, SEO poisoning, and supply chain attacks. They employ tools like , , and Rclone for credential theft, , and . The has both Windows and Linux variants, with specific functionality to target VMware ESXi servers in some Linux versions. The group's sophisticated tactics and potential ties to former Conti and Royal members make them a significant threat.

External references