BlackMatter launched as a ransomware-as-a-service operation focused on large enterprises in the US, UK, Canada, and Australia, seeking victims with at least $100 million in annual revenue and roughly 500 to 15,000 hosts. The group recruited initial access brokers on underground forums and offered up to $100,000 for exclusive network access, while advertising support for Windows, Linux, VMware ESXi, and NAS environments. Researchers and incident responders linked BlackMatter to DarkSide through overlapping targeting language, underground tradecraft, and technical similarities in the malware, including use of Salsa20 and RSA-1024; ransom demands reportedly reached $3 million to $4 million.
The operation presented itself as avoiding hospitals, government, defense, and critical infrastructure, but reporting tied it to attacks affecting major organizations and parts of critical U.S. infrastructure. By early November, BlackMatter told affiliates it was shutting down, saying pressure from local authorities had made part of the team unavailable and that its infrastructure would be taken offline within 48 hours, while decryptors would remain available on request. The closure followed mounting scrutiny that connected BlackMatter to DarkSide and FIN7, secret victim assistance from Emsisoft via a decryptor, and broader law-enforcement pressure on ransomware groups after high-profile incidents such as the Colonial Pipeline attack.

TTPs, infrastructure, and targeting history in one profile.
17 events from the most recent confirmed update back to the earliest known activity.
BlackMatter posted a shutdown message in its affiliate portal saying the operation was closing because of pressure from authorities and because part of its team was no longer available.
A GitHub repository published a 'DarkSide & BlackMatter Config Extractor' tool that parses embedded configuration data from ransomware samples into JSON. By version 1.0, the tool added support for BlackMatter 3.0 and exposed fields including ransom notes, AES and RSA keys, sample hashes, and malware version identifiers.
BlackMatter listed SolarBR, a major Coca-Cola bottler in Brazil, on its leak site and claimed to have stolen 50 GB of confidential data spanning finance, logistics, and development. The posting included a ransom deadline of August 23, 2021.
Researchers identified and reverse engineered a BlackMatter Linux ELF64 ransomware sample designed specifically for VMware ESXi servers. The sample used an "esxi_utils" library and the esxcli tool to enumerate ESXi details, disable the firewall, and forcibly shut down virtual machines before encryption.
According to the new reference, BlackMatter’s first observed campaign targeted a U.S.-based architecture company around July 28, 2021. This adds a specific early victim/campaign detail beyond prior general reporting that the group had begun attacking victims by late July.
On July 27, 2021, BlackMatter began distributing recruitment messages over Exploit's Jabber server, seeking experienced penetration testers for Windows and Linux environments as well as initial access suppliers. This marked a distinct expansion from its earlier forum post soliciting access to compromised corporate networks.
S2W Lab published reporting on Haron and identified multiple similarities to Avaddon, while stopping short of conclusively calling it a rebrand.
BlackMatter was introduced on cyber-underground forums and began advertising for initial access brokers to reach large corporate networks.
The first sample of Haron malware was submitted to VirusTotal, providing the earliest dated indicator of that separate ransomware group's emergence discussed alongside BlackMatter.
Flashpoint said BlackMatter registered accounts on the Russian-language underground forums XSS and Exploit, marking its early public emergence in cybercrime spaces.
By the end of July 2021, BlackMatter was actively attacking multiple corporate victims, targeting Windows, Linux, and ESXi systems and demanding roughly $3 million to $4 million.
A sample of BlackMatter ransomware was found in late July 2021, adding technical evidence of the group's active tooling.
As the operation emerged, BlackMatter established a dark web leak site that was still empty and published a claimed exclusion list covering hospitals, critical infrastructure, oil and gas, defense, nonprofits, and government.
BlackMatter launched operations in late July 2021, posting ads on Exploit and XSS for access to large networks in the US, UK, Canada, and Australia and offering up to $100,000 for qualifying access.
Analysis of a BlackMatter decryptor found the same distinctive Salsa20 and RSA-1024 encryption routines previously associated with DarkSide, strengthening claims that BlackMatter was a rebrand or successor.
One BlackMatter victim reportedly paid $4 million and in return received deletion of stolen data and decryptors for Windows and Linux ESXi systems.
Recorded Future analysts observed BlackMatter infrastructure earlier in the week and assessed a possible connection to the former DarkSide operation.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 66 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
13 references tracked. Mallory keeps watching after this page renders.
id-ransomware.blogspot.com
Open sourcevaronis.com
Open sourcetherecord.media
Open sourcegithub.com
Open sourcethreatpost.com
Open sourceflashpoint-intel.com
Open sourcetherecord.media
Open sourcerecordedfuture.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.