BlackSnake is a Windows ransomware strain assessed to be derived from the Chaos ransomware codebase. It combines conventional file-encryption extortion with cryptocurrency clipboard hijacking, making it notable for pairing ransomware activity with clipper functionality. The malware has been associated with an affiliate-oriented criminal operation and was advertised to recruit partners under a revenue-sharing model.
BlackSnake is implemented as a .NET Windows PE binary. It performs environment checks before execution and is designed to avoid infecting systems configured with Azerbaijani or Turkish language settings. To establish itself on a victim host, it copies itself into a user-profile application-data location under a masqueraded system-like name, checks for prior infection artifacts, prevents duplicate execution, and creates persistence through a Windows Run key.
A distinct feature of BlackSnake is its integrated clipper module. Running in a separate thread, this component monitors clipboard contents for cryptocurrency wallet patterns, specifically Bitcoin addresses, and replaces matching values with an attacker-controlled wallet. This enables theft of cryptocurrency transfers independently of the ransomware monetization path.
For extortion, BlackSnake enumerates files while excluding selected directories and paths, then encrypts a broad range of user data including documents, images, archives, databases, media, source code, and wallet-related files. It uses AES for file encryption and protects generated key material with a hardcoded RSA public key, appending encrypted key data to affected files. Encrypted files are renamed with a dedicated extension, and the malware drops a ransom note instructing victims on how to contact the operators.
BlackSnake is part of the broader evolution of Chaos-derived ransomware families that reuse and adapt leaked or shared builder code while adding differentiated monetization features. In BlackSnake’s case, the addition of clipboard hijacking expands its criminal utility beyond pure ransomware into opportunistic cryptocurrency theft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct technique documented for this family, organized by ATT&CK tactic.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Chaos-related ransomware variant (noted as a later variant in 2023) that uses full-file encryption; described as using AES + RSA and encrypting files across size ranges.
A later .NET Chaos-related variant (reported in 2023) that uses full-file encryption; described as using AES + RSA across targeted files.
A ransomware family based on Chaos ransomware source code that encrypts files, appends the .pay2unlock extension, drops an UNLOCK_MYFiles.txt ransom note, establishes persistence via Run registry keys, and includes an integrated clipper module that monitors the clipboard for Bitcoin wallet addresses and replaces them with an attacker-controlled address.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.