BLACKSUIT
ROYAL
CONTI
RansomwareCybercrimeIncident ResponseMay 30, 20248 min read

BlackSuit Ransomware Group

A rebranded version of Royal ransomware originating from the Conti gang, targeting healthcare, education, and critical infrastructure with devastating effect.

Scroll

BlackSuit ransomware, a rebranded version of the infamous Royal ransomware, emerged in May 2023. This strategic rebranding was an attempt to evade intensified law enforcement scrutiny. Originating from the notorious Conti ransomware gang, BlackSuit quickly targeted high-profile sectors such as healthcare, education, and critical infrastructure, causing widespread disruptions and significant financial losses.

Tactics, Techniques, and Procedures

BlackSuit ransomware employs a multifaceted approach to maximize the impact of their attacks:

1. Initial Access

2. Execution

3. Persistence

4. Privilege Escalation

5. Defense Evasion

6. Exfiltration and Impact

Indicators of Compromise

IOC Categories

Security teams should monitor for the following IOC categories: phishing domains used in campaigns, unusual activity involving network tunneling tools (Chisel, Cloudflared), unexpected use of remote access tools (AnyDesk, MobaXterm), and file extensions or naming conventions indicative of BlackSuit's encryption process.

How Mjolnir Security Can Help

Mjolnir Security offers a comprehensive suite of services to protect against threats like BlackSuit ransomware:

Incident ResponseThreat AnalysisProactive Threat Hunting24/7 MonitoringVulnerability ManagementPatch DeploymentEmployee TrainingBackup & RecoveryMFA EnforcementNetwork Segmentation
  • Incident Response and Threat Analysis: Our experienced team rapidly identifies and mitigates threats, minimizing damage and downtime.
  • Proactive Threat Hunting and Monitoring: Continuous monitoring of network activity to detect and respond to malicious activities in real time.
  • Vulnerability Management and Patch Deployment: Regular assessments to identify and remediate vulnerabilities in software and hardware.
  • Employee Training and Awareness Programs: Comprehensive training programs to educate staff on phishing techniques and social engineering tactics.
  • Robust Backup and Recovery Solutions: Implementing encrypted and immutable offline backups to ensure data can be restored without paying a ransom.
  • Multi-Factor Authentication and Network Segmentation: Enforcing MFA across all critical systems and isolating critical networks to limit lateral movement.
Written by: Mjolnir Security  |  Published: May 30, 2024