Royal Ransomware Actors Rebrand as “BlackSuit”


The FBI and CISA recently published an update to the joint Cybersecurity Advisory “#StopRansomware: Royal Ransomware.” The updated advisory provides network defenders with recent and historically observed tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) associated with BlackSuit variants (previously Royal).

FBI investigations identified these TTPs and IOCs as recently as July 2024. See WaterISAC’s coverage of the last two updates to the Joint Advisory. As of August 2024, BlackSuit ransomware attacks have spread across numerous critical infrastructure sectors. BlackSuit conducts data exfiltration and extortion prior to encryption and then publishes victim data to a leak site if a ransom is not paid.

Read more…
Source: Water ISAC


Sign up for our Newsletter


Related:

  • Cyber criminals are launching phishing attacks on LinkedIn

    August 25, 2022

    Regular users of LinkedIn, the professional networking and social working platform, have noticed an increase of threat actors trying to steal critical personal information through phishing attacks. These cyber criminals are using false LinkedIn accounts to trick unsuspecting victims into giving up confidential information. How are they doing it? Threat actors start by creating fraudulent LinkedIn ...

  • CISA: Preparing Critical Infrastructure for Post-Quantum Cryptography

    August 24, 2022

    Nation-states and private companies are actively pursuing the capabilities of quantum computers. Quantum computing opens up exciting new possibilities; however, the consequences of this new technology include threats to the current cryptographic standards. These standards ensure data confidentiality and integrity and support key elements of network security. While quantum computing technology capable of breaking public ...

  • Ransomware Actor Abuses Genshin Impact Anti-Cheat Driver to Kill Antivirus

    August 24, 2022

    There have already been reports on code-signed rootkits like Netfilter, FiveSys, and Fire Chili. These rootkits are usually signed with stolen certificates or are falsely validated. However, when a legitimate driver is used as a rootkit, that’s a different story. Such is the case of mhyprot2.sys, a vulnerable anti-cheat driver for the popular role-playing game ...

  • Lloyd’s to exclude certain nation-state attacks from cyber insurance policies

    August 24, 2022

    Lloyd’s of London insurance policies will stop covering losses from certain nation-state cyber attacks and those that happen during wars, beginning in seven months’ time. In a memo sent to the company’s 76-plus insurance syndicates, underwriting director Tony Chaudhry said Lloyd’s remains “strongly supportive” of cyber attack coverage. However, as these threats continue to grow, they ...

  • New ‘Donut Leaks’ extortion gang linked to recent ransomware attacks

    August 23, 2022

    A new data extortion group named ‘Donut Leaks’ is linked to recent cyberattacks, including those on Greek natural gas company DESFA, UK architectural firm Sheppard Robson, and multinational construction company Sando. Two victims disclosed these attacks without much information regarding who was involved. Over the weekend, DESFA confirmed they suffered a cyberattack after Ragnar Locker leaked screenshots ...

  • Legitimate SaaS Platforms Being Used to Host Phishing Attacks

    August 23, 2022

    Instead of creating phishing pages from scratch, more and more cybercriminals are now abusing legitimate software-as-a-service (SaaS) platforms, including various website builders or form builders, to host their phishing pages. Since these URLs are hosted on legitimate domains, they can be especially difficult for many phishing detection engines to detect. Furthermore, these platforms typically require ...