BlackSuit Ransomware

Description Summary

BlackSuit ransomware is a direct evolution of (and rebrand from) Royal ransomware, first observed in mid-2023. It shares significant code overlap with Royal and continues the same operational tradecraft — partial encryption, data theft for double extortion, and targeting of large-revenue organizations. BlackSuit has both Windows and Linux/ESXi variants.

Threat Actor

Same actor cluster as Royal (former Conti Team 1).

Technical Indicators

Encryption Extension
.blacksuit
Encryption Algorithm
AES-256 + RSA
Ransom Note Name
README.BlackSuit.txt
Targeted Industries
Critical manufacturing, Education, Healthcare, Government facilities
First Seen
May 2023
Last Seen
Active until July 2025 — SEIZED (Operation Checkmate); successor: Chaos
Geographical Location
United States, United Kingdom, Canada, Europe

MITRE ATT&CK Matrix

Tactic TTP Technique Name
Initial Access x 3 T1566 Phishing
T1190 Exploit Public-Facing Application
T1078 Valid Accounts
Execution x 1 T1059 Command and Scripting Interpreter
Execution Persistence x 1 T1053 Scheduled Task/Job
Defense Evasion x 2 T1562.001 Disable or Modify Tools
T1070.004 File Deletion
Discovery x 2 T1083 File and Directory Discovery
T1082 System Information Discovery
Lateral Movement x 2 T1021.001 Remote Services: RDP
T1021.002 SMB/Windows Admin Shares
Exfiltration x 2 T1041 Exfiltration Over C2 Channel
T1567.002 Exfiltration to Cloud Storage
Impact x 4 T1486 Data Encrypted for Impact
T1490 Inhibit System Recovery
T1489 Service Stop
T1486 Partial Encryption (configurable %)