Skip to main content
Mallory
MalwareRansomwareUsed by 5 actors

BlackSuit

Also known asRoyal

BlackSuit is a ransomware family and operation closely associated with Royal and the broader Conti lineage. The provided content indicates that Royal began testing a new encryptor called BlackSuit in 2023, with researchers identifying clear similarities between the BlackSuit and Royal encryptors, including overlapping code characteristics, command-line arguments, file exclusions, and intermittent encryption behavior. Multiple sources in the content describe Royal as a successor to Conti and state that Royal later rebranded to BlackSuit in 2024, while other reporting characterizes BlackSuit operators as former Royal/Conti members.

The malware is used in enterprise-targeting ransomware intrusions and has been observed in limited attacks under its own branding, including use of dedicated negotiation infrastructure and leak-site branding. BlackSuit is also referenced as one of the more prevalent ransomware variants observed in 2024 and as a significant ransomware brand affected by later law-enforcement action. Sophos reporting in the content describes BlackSuit as a descendant of Conti and links it to clustered intrusion activity overlapping with Hive, Royal, and Black Basta operations, including use of batch scripts such as file1.bat, file2.bat, and gp.bat; creation of rogue administrative accounts; scheduled-task persistence; deployment of ransomware from password-protected .7z archives named after the victim; use of Cobalt Strike, PowerShell, PsExec, and RDP; NTDS and registry hive dumping; and data exfiltration with rclone.

Behaviorally, the content explicitly states that Royal can delete Volume Shadow Copy backups using vssadmin.exe delete shadows /all /quiet, and BlackSuit is described as sharing substantial technical overlap with Royal’s tooling. BlackSuit has also been observed in attack sequences following EDR-killer activity. The content ties BlackSuit/Royal to high-impact victimization, including municipal and enterprise environments, and places the operation within the evolving post-Conti ransomware ecosystem alongside brands such as Zeon and Royal. High-confidence aliases in the provided content are BlackSuit and Royal, though the content distinguishes BlackSuit as the newer encryptor/brand rather than simply a synonym in all contexts.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Conti

"Royal ransomware is following in the same path, a new variant targeting Linux systems emerged... Royal’s Linux counterpart also targets ESXi servers"; "In its early campaigns, Royal deployed BlackCat’s encryptor, but later shifted to its own called Zeon".

via trend micro researchtrendmicro.com
blacksuite_ransomware_gang

...BlackSuite Ransomware Gang...

via picus security blogpicussecurity.com
BlackSuit Ransomware Actors

“…BlackSuit ransomware actors breached CDK Global… strongly suggesting it is rebranding of Royal ransomware.”

via verizon businessverizon.com
Stern

...Stern has transacted with addresses linked to strains like Quantum, Karakurt, Diavol, and Royal in 2022 following Conti’s demise.

via chainalysis blogchainalysis.com
DEV-0569

"Since approximately September 2022, cyber threat actors have compromised U.S. and international organizations with Royal ransomware."

via ic3 alertsic3.gov
MITRE ATT&CK

Techniques & procedures

22 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

1 technique
T1566PhishingEvidence1

Execution

4 techniques
T1059Command and Scripting InterpreterEvidence1
TacticExecution

These similarities include command line arguments, code similarities, file exclusions, and similar intermittent encryption techniques.

T1059.003Windows Command ShellEvidence1
TacticExecution

the use of the same batch scripts and files: file1.bat, file2.bat, ip.txt, and gp.bat

T1059.012Hypervisor CLIEvidence1
TacticExecution
T1106Native APIEvidence1
TacticExecution

Stealth

1 technique
T1070.004File DeletionEvidence1
TacticStealth

file2.bat : a second batch file, executed in Safe Mode via a registry key, designed to unpack the ransomware binary from the encrypted archive

Discovery

8 techniques
T1016System Network Configuration DiscoveryEvidence3
TacticDiscovery

Royal can scan the network interfaces of targeted systems. LightSpy reads the host's Wi‑Fi connection history and utilizes Apple's CWWiFiClient API to scan for nearby Wi‑Fi networks and obtain SSID, security type, and RSSI values.

T1046Network Service DiscoveryEvidence2
TacticDiscovery

The content repeatedly describes threat actors and malware performing network scanning, port scanning, service enumeration, OS fingerprinting, and identifying open ports/services across victim environments.

T1057Process DiscoveryEvidence3
TacticDiscovery

The content repeatedly describes malware and threat actors obtaining lists of running processes, using utilities such as tasklist, ps, WMI, Get-Process, CreateToolhelp32Snapshot, EnumProcesses, and similar APIs/commands to enumerate active processes on victim systems.

T1082System Information DiscoveryEvidence5
TacticDiscovery

The content repeatedly describes malware and threat actors collecting host details such as OS version, hostname, architecture, CPU, memory, BIOS, domain, language, and other configuration data; e.g., "APT41 uses multiple built-in commands such as systeminfo and net config Workstation to enumerate victim system basic configuration information."

T1083File and Directory DiscoveryEvidence2
TacticDiscovery

"...has a command to retrieve metadata for files on disk as well as a command to list the current working directory." / "...can list files and directories." / "...used the following commands... to obtain information about files and directories: dir c:\ >> %temp%\download ..."

T1120Peripheral Device DiscoveryEvidence1
TacticDiscovery

"Babuk can enumerate disk volumes, get disk information"; "Ryuk has called GetLogicalDrives ... and GetDriveTypeW"; "Cuba can enumerate local drives, disk type, and disk free space"; "Chimera ... fsutil fsinfo drives"

T1135Network Share DiscoveryEvidence1
TacticDiscovery
T1680Local Storage DiscoveryEvidence1
TacticDiscovery

Lateral Movement

1 technique
T1021.002SMB/Windows Admin SharesEvidence1
T1105Ingress Tool TransferEvidence1

The group employs Royal and BlackSuit lockers, with Emotet and IcedID as precursors. They prioritize alternatives to CobaltStrike, particularly Sliver, and develop custom precursor loaders.

Exfiltration

2 techniques
T1041Exfiltration Over C2 ChannelEvidence2

Zolotarjovs was specifically tasked with analyzing data stolen from victims, researching the companies and using the information to force victims into paying.

T1567Exfiltration Over Web ServiceEvidence3

When the ransom demand was not met, he allegedly encouraged co-conspirators to leak or sell the data.

Impact

3 techniques
T1486Data Encrypted for ImpactEvidence11
TacticImpact

...his involvement in a series of ransomware attacks... | A federal judge sentenced a Latvian national ... for his involvement in a series of ransomware attacks ... helped an organization led by former leaders of the Conti ransomware group extort payments from more than 54 companies.

T1490Inhibit System RecoveryEvidence2
TacticImpact

Akira will delete system volume shadow copies via PowerShell commands. Avaddon deletes backups and shadow copies using native system tools. Babuk has the ability to delete shadow volumes using vssadmin.exe delete shadows /all /quiet. BlackCat can delete shadow copies using vssadmin.exe delete shadows /all /quiet and wmic.exe Shadowcopy Delete; it can also modify the boot loader using bcdedit /set {default} recoveryenabled No.

T1657Financial TheftEvidence5
TacticImpact

He analyzed stolen data and used sensitive information to intensify extortion tactics. When the ransom demand was not met, he allegedly encouraged co-conspirators to leak or sell the data. Court documents reveal he distributed a bulk set of sensitive records to hundreds of patients, aiming to amplify fear and force compliance.

Other

1 technique
T1562.009Safe Mode BootEvidence1

file1.bat : a batch file designed to set up the system with autologon as the newly-created administrative user AdminBac, reboot into Safe Mode ... file2.bat : a second batch file, executed in Safe Mode via a registry key, designed to unpack the ransomware binary from the encrypted archive

INDICATORS OF COMPROMISE

IOCs tracked for this family

4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
1 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
3 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in app1 month ago
hash.sha256●●●●●●●●●●●●View more in app2 years ago
hash.md5●●●●●●●●●●●●View more in app2 years ago
hash.sha1●●●●●●●●●●●●View more in app2 years ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching4

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution5

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping22

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.