1 min read
FunkSec: A Top Ransomware Group Leveraging AI
Originally published: 02/11/2025 I. Targeted Entities Government Healthcare Manufacturing Media Technology II. Introduction An emerging ransomware...
Published 07/24/2024
New Indicators of Compromise associated with BlackSuit ransomware have been found in recent attacks. BlackSuit is a sophisticated cyber threat known for its double-extortion tactics, encrypting and exfiltrating victims' data to demand a ransom.
BlackSuit ransomware emerged as a prominent threat actor in the cyber landscape in 2023. It is believed to be a direct successor to the Royal ransomware, itself a descendant of the notorious Conti ransomware group. BlackSuit shares significant code similarities with Royal, including encryption algorithms and communication methods, indicating that the operators behind BlackSuit have inherited and improved upon Royal’s techniques. An analysis by Trend Micro revealed that BlackSuit and Royal ransomware have a high degree of similarity, with 98% similarity in functions, 99.5% in blocks, and 98.9% in jumps. Additionally, BlackSuit employs command-line arguments similar to those used by Royal, though with some variations and additional options.
This technical sophistication has enabled BlackSuit to carry out multiple high-profile attacks across various sectors since its emergence. Notably, one of the most significant attacks targeted a U.S.-based healthcare provider in October 2023, resulting in severe operational disruptions. The financial losses from this attack were estimated at millions, including ransom payments and recovery and mitigation costs. In another incident, an educational institution experienced a data breach, exposing sensitive student and staff information.
Financial gain is the primary motivation behind BlackSuit attacks. The group employs double-extortion tactics, demanding a ransom not only to decrypt the data but also to prevent its public release. This strategy increases the pressure on victims to pay the ransom, highlighting the ruthlessness and effectiveness of BlackSuit’s extortion methods.
These tools allow BlackSuit to conduct reconnaissance, maintain persistence, and execute their ransomware effectively. The group’s preference for leveraging legitimate software tools makes their activities harder to detect and mitigate. Understanding the tools and methods used by BlackSuit ransomware is critical to defending against its attacks.
| File Name | Description | SHA-1 Hash | Virus Total Detections |
| psexec.exe | PsExec | 078163d5c16f64caa5a14784323fd51451b8c831c73396b967b4e35e6879937b | 2 |
| decryptor.exe | Blacksuit Ransomware | 141c7c7a2dea1be7304551a1fa0d4e4736e45b079f48eb8ff4c45d6a033b995a | 51 |
| netscan.exe | NetScan | 18f0898d595ec054d13b02915fb7d3636f65b8e53c0c66b3c7ee3b6fc37d3566 | 32 |
| sqlite.dll | Suspected information-stealing malware | 5c297d9d50d0a784f16ac545dd93a889f8f11bf37b29f8f6907220936ab9434f | 38 |
| pskill.exe | PsKill | 5ef168f83b55d2cbd2426afc5e6fa8161270fa6a2a312831332dc472c95dfa42 | 1 |
| rclone.exe | Rclone | d9a8c4fc94655f47a127b45c71e426d0f2057b6faf78fb7b86ee2995f7def41d | 2 |
| ProcessHacker.exe | ProcessHacker | bd2c2cf0631d881ed382817afcce2b093f4e412ffb170a719e2762f250abfea4 | 29 |
|
Network IOCs |
Virus Total Detections |
| 185.73.125[.]96 | 10 |
Blacksuit (2024) SentinelOne. Available at: https://www.sentinelone.com/anthology/blacksuit/ (Accessed: 08 June 2024).
Montalbano, E. (2024) BlackSuit claims dozens of victims with ransomware, BlackSuit Claims Dozens of Victims With Ransomware. Available at: https://www.darkreading.com/cyberattacks-data-breaches/blacksuit-dozens-victims-curated-ransomware (Accessed: 08 June 2024).
Contributing Security Analysts: Yousef Blassy, Thiago Pagliaroni, Yousef Aref, Abdullah Siddiqi, and Nahyan Jamil.
1 min read
Originally published: 02/11/2025 I. Targeted Entities Government Healthcare Manufacturing Media Technology II. Introduction An emerging ransomware...
1 min read
Originally Published May 13, 2025
1 min read
Published 07/08/2024