A cyberattack on German fuel logistics operators Oiltanking and Mabanaft, both subsidiaries of Marquard & Bahls, disrupted terminal operations and inland fuel supply, forcing companies including Shell and BP Aral to reroute deliveries and rely on alternative depots. Oiltanking said it detected the incident on January 29, after which some terminals operated at limited capacity and both firms declared force majeure for affected activities. Germany’s BSI described the case as serious and said the disruption affected fuel stations in northern Germany, with some sites reportedly switching to manual processes.
An internal BSI report later attributed the intrusion to BlackCat (also tracked as ALPHV), a Rust-based ransomware-as-a-service operation that emerged in late 2021 and targets both Windows and Linux environments. Security research linked BlackCat to earlier BlackMatter activity through shared tooling such as the Fendr/ExMatter exfiltration utility and overlapping tactics used in double-extortion campaigns, extending a lineage that researchers and U.S. authorities have also associated with DarkSide rebranding. The incident underscored how ransomware operations tied to that ecosystem continued to affect critical supply chains despite public claims by predecessor groups that they would avoid oil and gas targets.

TTPs, infrastructure, and targeting history in one profile.
15 events from the most recent confirmed update back to the earliest known activity.
Palo Alto Networks Unit 42 published a threat assessment on BlackCat ransomware, documenting its Rust-based malware, affiliate model, and ransom practices. The report described BlackCat as a newly emerged ransomware-as-a-service group.
A prominent Korean manufacturing company suffered a DarkSide ransomware infection affecting many internal systems in January 2022. AhnLab later found the ransomware had been distributed through Active Directory Group Policy.
Kaspersky researchers found BlackCat extensively used a modified version of the Fendr, or ExMatter, exfiltration tool to steal corporate data before encryption. The activity was observed during December 2021 and January 2022 and linked BlackCat to prior BlackMatter operations.
Unit 42 reported that BlackCat, also known as ALPHV, emerged in mid-November 2021 as a ransomware-as-a-service operation. The group used a Rust-based encryptor and targeted both Windows and Linux systems.
CISA, the FBI, and the NSA released a joint advisory detailing BlackMatter's tactics, ransom demands, targeting, and mitigations. The advisory said BlackMatter had been targeting U.S. critical infrastructure since July 2021 and may be a DarkSide rebrand.
Starting in July 2021, BlackMatter targeted multiple U.S. critical infrastructure entities, including two organizations in the Food and Agriculture Sector. This marked the group's early operational activity documented by CISA, FBI, and NSA.
BlackMatter began operating as a ransomware-as-a-service group in July 2021, according to later U.S. government reporting. The group was assessed as a possible rebrand of DarkSide.
Kaspersky researchers reported new evidence connecting BlackCat to BlackMatter, including BlackCat's reuse and modification of the custom exfiltration tool Fendr/ExMatter. The findings added to earlier observations of overlap between the two ransomware operations.
An internal BSI report obtained by Handelsblatt said the BlackCat ransomware group was behind the cyberattack on Oiltanking and Mabanaft. The report said Oiltanking's systems were compromised through a previously unknown gateway.
Germany's Federal Office for Information Security said it was providing expertise on the incident, and its president Arne Schönbohm described it as serious but not grave. He said 233 fuel stations in northern Germany were affected.
Shell rerouted oil supplies to alternative depots, while BP's Aral network sourced fuel from alternative supplies after the attack disrupted Oiltanking operations. Reuters reported the measures as part of the response to the German fuel logistics outage.
Following the January 29 incident, Oiltanking terminals in Germany operated with limited capacity and both Oiltanking and Mabanaft declared force majeure for affected operations. The disruption affected fuel distribution in northern Germany and forced some stations to use manual processes.
Oiltanking and Mabanaft discovered a cyberattack that disrupted IT systems and supply-chain operations. Oiltanking said it detected the initial incident on January 29 and began working with external specialists and authorities.
Operators linked to DarkSide and BlackMatter moved about 107 BTC, valued at roughly $6.8 million, and split the funds across multiple wallets. Profero assessed the movement as preparation for laundering or cashing out rather than a law enforcement seizure.
In an interview, a BlackMatter representative said the group had developed its ransomware over six months, was recruiting affiliates, and had already attacked companies not yet publicly listed. The group also claimed it would avoid sectors such as healthcare, critical infrastructure, oil and gas, and government.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 27 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
8 references tracked. Mallory keeps watching after this page renders.
asec.ahnlab.com
Open sourcethehackernews.com
Open sourcereuters.com
Open sourceunit42.paloaltonetworks.com
Open sourcezdnet.com
Open sourcetherecord.media
Open sourceus-cert.cisa.gov
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.