A major global equipment manufacturer suffered a severe ransomware attack orchestrated by the BlackSuit ransomware group, also known as Ignoble Scorpius. The attack began with a vishing (voice phishing) campaign in which an attacker impersonated the company's IT help desk and convinced an employee to enter their VPN credentials into a phishing site. Using these stolen credentials, the attackers gained initial access to the corporate network. Once inside, they escalated privileges by executing a DCSync attack on a domain controller, allowing them to steal highly privileged credentials, including those of a key service account. The attackers then moved laterally across the network using Remote Desktop Protocol (RDP), Server Message Block (SMB), and tools such as Advanced IP Scanner and SMBExec to map the environment and identify valuable assets. Persistence was established by deploying AnyDesk and a custom remote access trojan (RAT) as scheduled tasks on domain controllers. The threat actors compromised a second domain controller and extracted the NTDS.dit database, which contains all user password hashes, enabling further credential compromise. Over 400 GB of sensitive data was exfiltrated using a renamed rclone utility. To erase forensic evidence and hinder incident response, the attackers deployed CCleaner before launching the ransomware payload. The BlackSuit ransomware was deployed using Ansible, resulting in the simultaneous encryption of hundreds of virtual machines across nearly 60 VMware ESXi hosts, causing widespread operational disruption. The attackers demanded a $20 million ransom, which the organization refused to pay. In response, the manufacturer implemented several security measures, including upgrading to newer Cisco Adaptive Security Appliance firewalls, enforcing multi-factor authentication, segmenting the network, deactivating NTLM, and restricting administrative access to isolated VLANs. The incident highlights the significant risks posed by social engineering and credential theft, as well as the sophisticated tactics used by modern ransomware groups. The attack demonstrates the importance of robust incident response, credential hygiene, and layered security controls to mitigate the impact of such breaches. The use of legitimate remote access tools and living-off-the-land techniques by the attackers complicated detection and response efforts. The exfiltration of large volumes of sensitive data prior to encryption underscores the dual extortion tactics now common among ransomware operators. The manufacturer’s refusal to pay the ransom and rapid implementation of enhanced security controls serve as a case study in post-incident resilience. The attack also illustrates the growing trend of targeting virtualization infrastructure, such as VMware ESXi hosts, to maximize operational disruption. Security researchers and incident responders continue to analyze the tactics, techniques, and procedures (TTPs) used in this attack to inform defensive strategies for other organizations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
SC Media reported that hacked VPN credentials facilitated the disruptive BlackSuit ransomware intrusion, echoing the key access vector and impact described in the earlier technical analysis. This is a reporting development rather than a new attack event.
Palo Alto Networks Unit 42 released a public write-up detailing the anatomy of the BlackSuit attack against the global equipment manufacturer, providing technical analysis of how the incident unfolded.
After gaining access, the threat actors carried out a disruptive ransomware attack attributed to BlackSuit against the manufacturer, escalating from unauthorized access to operational impact. The reporting indicates a full intrusion sequence rather than a separate unrelated event.
Attackers obtained access to a global equipment manufacturer’s network using stolen or hacked VPN credentials, establishing the initial foothold for the intrusion described in the BlackSuit incident. The exact intrusion date is not specified in the references.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.