BlackMatter was a ransomware-as-a-service operation that emerged in July 2021 and is widely assessed as a successor or rebrand of DarkSide, with some reporting also noting overlaps in personnel, tradecraft, and code similarities with REvil. The group focused on big-game hunting against large enterprises, typically seeking victims with annual revenue above $100 million, and explicitly solicited access to corporate networks in the United States, Canada, the United Kingdom, and Australia. Although it publicly claimed to avoid certain sectors such as healthcare, government, and parts of critical infrastructure, it was linked to attacks affecting U.S. critical infrastructure entities, including organizations in food and agriculture and blood testing. BlackMatter operated an affiliate model and recruited initial access brokers, penetration testers, and other partners on Russian-language criminal forums. It maintained a leak site and used data theft to pressure victims, making it part of the modern double-extortion ransomware ecosystem. The operation was also associated with Exmatter, a custom exfiltration tool used to selectively steal business-relevant files before encryption. Exmatter enumerated logical drives, prioritized recently modified files, and exfiltrated targeted data primarily over SFTP with WebDAV as a fallback, then attempted anti-forensic self-deletion. The malware family targeted primarily Windows enterprise environments, while also developing Linux tooling for VMware ESXi environments. Reporting indicates BlackMatter used tailored payloads per victim, native Windows cryptography, partial file encryption to accelerate impact, shadow-copy deletion, Active Directory enumeration, and HTTP or HTTPS communications with command-and-control infrastructure. It has also been described as using Linux payloads for pivoting and, separately, a Linux encryptor specifically designed for ESXi that leveraged ESXi management utilities to enumerate virtual machines, disable the firewall, forcibly stop virtual machines, and then encrypt virtualized infrastructure. Public analysis also linked BlackMatter to custom and distinctive encryption routines shared with DarkSide. BlackMatter’s intrusion activity was associated with exploitation of vulnerable internet-facing services and the abuse of compromised credentials, including remote desktop, VPN, and virtualization infrastructure. The group also advertised for purchased access rather than relying solely on self-obtained footholds. Across reporting, BlackMatter is characterized as a financially motivated cybercriminal enterprise rather than a state-directed actor. The operation was short-lived but influential. It became notable both for attacks on large organizations and because defenders identified a cryptographic flaw that enabled recovery for some victims without ransom payment before the operators corrected it. BlackMatter is also relevant historically because later ransomware operations, especially BlackCat/ALPHV and some LockBit 3.0 variants, showed strong operational or code-level continuity with BlackMatter tooling and techniques.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
58 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
72 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a successor branding of DarkSide.
Mentioned only for comparison of Tor payment site and user verification similarities with Agenda.
RaaS/extortion group operating BlackMatter ransomware against large enterprises, using double extortion, recruiting initial access brokers, and targeting high-revenue corporate networks globally.
Mentioned as a comparison and in discussion of possible operational similarities with BlackCat.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.