A Georgia county school district was listed as a victim by the BlackSuit ransomware gang, adding to evidence that the group is actively targeting public-sector organizations. The incident was reported after the gang posted the district on its leak site, a tactic commonly used to pressure victims by threatening publication of stolen data.
The claim followed a joint CISA and FBI warning that the Royal ransomware operation may have rebranded as BlackSuit. U.S. authorities said the group uses familiar double-extortion tactics, combining file encryption with data theft, and warned organizations to harden defenses against phishing, remote access abuse, and other intrusion methods associated with the Royal/BlackSuit operators.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
BlackSuit listed a Georgia county school district on its leak site, indicating it had allegedly compromised the district and was attempting to extort it.
CISA and the FBI issued a warning that the Royal ransomware operation appeared likely to rebrand as BlackSuit, linking the newer name to the existing threat actor.
Researchers reported that the Royal ransomware gang had started testing and using a new encryptor called BlackSuit, with strong code and behavior overlap linking it to Royal. The activity suggested BlackSuit was emerging as part of Royal’s tooling months before later warnings about a possible rebrand.
Trend Micro published research assessing that BlackSuit shared similarities with Royal ransomware and may be a variant by the same authors, a copycat, or a splinter or affiliate tied to the Royal ecosystem. The report also documented BlackSuit deleting Windows shadow copies via vssadmin as part of its behavior.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
cybernews.com
Open sourcetherecord.media
Open sourcebleepingcomputer.com
Open sourcetrendmicro.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.