BlackMatter was a ransomware-as-a-service operation that emerged in mid-2021 after the apparent disruption of DarkSide and REvil, and is widely assessed as closely connected to DarkSide through personnel, tradecraft, and design overlap. The group recruited affiliates on Russian-language cybercrime forums, required substantial vetting and deposits from selected partners, and sought both established intruders and brokers able to provide access to enterprise networks. BlackMatter focused on large private-sector organizations, especially companies with annual revenue above $100 million, and publicly stated that it avoided government, healthcare, non-profit, defense, and several critical-infrastructure sectors, although such self-imposed restrictions were not consistently reliable in practice. BlackMatter combined file encryption with data theft and leak-site pressure, making it a double-extortion actor. It operated a Tor-based extortion and publication platform and emphasized that victims were more likely to pay when both operational disruption and exposure of stolen data were at stake. Reporting also links the operation to custom exfiltration tooling later reused by ALPHV/BlackCat. The group advertised that it had incorporated ideas from DarkSide, REvil, and LockBit, and technical analysis found meaningful similarities with DarkSide in multithreaded partial encryption, runtime API resolution, string decryption, privilege elevation, ransom-wallpaper behavior, and administrative panel design. Observed BlackMatter tradecraft included affiliate-driven initial access via purchased or pre-existing network access, PowerShell-based deployment, Safe Mode reboot encryption, UAC bypass, AutoAdminLogon configuration to resume execution after reboot, process termination, and broad enterprise encryption. The malware and associated operators also demonstrated defense-evasion behavior through runtime decryption and API resolution, and post-compromise activity consistent with credential abuse, lateral movement, and data exfiltration. BlackMatter was associated with attacks against corporate networks in the United States, Canada, Australia, and Great Britain, and later reporting connected its operators or affiliates to successor ecosystems including LockBit Black and ALPHV/BlackCat. The operation shut down in late 2021 under sustained law-enforcement pressure, but its personnel, tooling lineage, and affiliate relationships appear to have persisted through subsequent rebrands and successor ransomware programs.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
41 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
23 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a successor branding of DarkSide.
RaaS/extortion group operating BlackMatter ransomware against large enterprises, using double extortion, recruiting initial access brokers, and targeting high-revenue corporate networks globally.
Mentioned as another threat actor associated with use of the same UAC bypass technique referenced in the SilabRAT analysis.
Uses registry modifications adding DefaultUserName and DefaultPassword under Winlogon to enable auto admin logon, allowing compromised hosts to automatically log on and continue ransomware encryption after a safe mode boot.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.