Send Email
Confidentiality Guaranteed
Confidentiality Guaranteed

Private investigator

Law enforcement has seized the darkish web extortion web sites of the BlackSuit ransomware operation, which has targeted and breached the networks of a entire bunch of organizations worldwide over the previous so a lot of years.
The U.S. Division of Justice confirmed the takedown in an e-mail earlier at the present time, asserting the authorities all in favour of the action executed a court docket-licensed seizure of the BlackSuit domains.
Earlier at the present time, the web sites on the BlackSuit .onion domains had been replaced with seizure banners asserting that the ransomware gang’s web sites had been taken down by the U.S. Fatherland Safety Investigations federal law enforcement agency as allotment of a joint global action codenamed Operation Checkmate.
“This site has been seized by U.S. Homeland Security Investigations as part of a coordinated international law enforcement investigation,” the banner reads.
BleepingComputer has confirmed that the seized web sites encompass darkish web records leak blogs and negotiation web sites outdated to extort victims into paying ransom demands.
Other law enforcement authorities that participated in this joint operation encompass the U.S. Secret Carrier, the Dutch National Police, the German Hiss Criminal Police Place of job, the U.Okay. National Crime Agency, the Frankfurt Overall Prosecutor’s Place of job, the Justice Division, the Ukrainian Cyber Police, Europol, and others.
A spokesperson for Romanian cybersecurity company Bitdefender also told BleepingComputer that its cybercrime unit (is named Draco Crew) equipped cybersecurity consulting and steering to law enforcement partners for the period of Operation Checkmate.
“We commend our law enforcement partners for their coordination and determination. Operations like this reinforce the critical role of public-private partnerships in tracking, exposing, and ultimately dismantling ransomware groups that operate in the shadows,” Bitdefender acknowledged.

On Thursday, the Cisco Talos possibility intelligence learn team reported that it had chanced on evidence suggesting the BlackSuit ransomware gang is vulnerable to rebrand itself once extra as Chaos ransomware.
“Talos assesses with moderate confidence that the new Chaos ransomware group is either a rebranding of the BlackSuit (Royal) ransomware or operated by some of its former members,” the researchers acknowledged.
“This assessment is based on the similarities in TTPs, including encryption commands, the theme and structure of the ransom note, and the use of LOLbins and RMM tools in their attacks.”
BlackSuit started as Quantum ransomware in January 2022 and is believed to be a in an instant successor to the infamous Conti cybercrime syndicate. Whereas they first and predominant outdated encryptors from assorted gangs (such as ALPHV/BlackCat), they deployed their very private Zeon encryptor rapidly after and rebranded as Royal ransomware in September 2022.
In June 2023, after focused on the City of Dallas, Texas, the Royal ransomware gang began working under the BlackSuit name, following the checking out of a unique encryptor known as BlackSuit amid rumors of a rebranding.
CISA and the FBI first published in a November 2023 joint advisory that Royal and BlackSuit allotment identical tactics, while their encryptors show glaring coding overlaps. The identical advisory linked the Royal ransomware gang to attacks focused on over 350 organizations worldwide since September 2022, resulting in ransom demands exceeding $275 million.
The 2 companies confirmed in August 2024 that the Royal ransomware had rebranded as BlackSuit and had demanded over $500 million from victims since surfacing extra than two years prior.
Update 7/24/25: Updated article to encompass that negotiation web sites had been seized as effectively.
Receive rising threats in loyal time – forward of they affect your alternate.
Study how cloud detection and response (CDR) presents security teams the sting they need on this shining, no-nonsense info.
