Skip to main content

Operator dossier

Blacksuit (also tracked as black suit) is a ransomware operator no longer publishing new disclosures. Darkfield has indexed 184 public victims claimed by this operator between June 12, 2023 and June 2, 2025. Blacksuit is a financially motivated ransomware group that emerged in June 2023, quickly establishing itself as a significant threat with 184 documented victims across multiple sectors. The group's origin and specific affiliations remain largely undocumented in public threat intelligence reports, though their operational patterns suggest they operate as an independent entity rather than a traditional RaaS model. Blacksuit primarily targets organizations through common initial access vectors and employs standard ransomware deployment techniques, though detailed technical analysis of their specific encryption methods and whether they consistently employ double extortion tactics has not been widely published by major security firms. The group has demonstrated a clear preference for targeting business services, healthcare, government, and manufacturing sectors, with their victims predominantly located in English-speaking countries including the United States, United Kingdom, and Canada, as well as Spain and Germany. As of current reporting, Blacksuit remains an active ransomware operation with no publicly documented law enforcement disruptions or significant rebranding efforts.

Most-targeted sectors

Most-affected countries

Recent disclosures by Blacksuit

Most recent 150 of 184 indexed disclosures. Click any row for the full per-victim dossier.

See every disclosure indexed for Blacksuit

How we know this. Operator profiles on Darkfield are built from continuous monitoring of every leak site the group is known to operate, cross-correlated with community-curated feeds (RansomLook, ransomware.live, RansomWatch, MISP-galaxy). Status flips from active to inactive when no new disclosure appears for 60 days. MITRE ATT&CK mappings shown in the interactive section below are sourced from CISA, vendor analysis, and the MITRE community catalog — we attribute each technique back to its source. Aliases reflect operator re-brands and affiliate splits.

Inactive ransomware operator

All groups

Blacksuit

aka black suit · 184 victims indexed · first seen 3 years ago · last activity 1 year ago

184
Victims indexed
#47 of 370 tracked operators
2y 0m
Active period
Jun 2023 → Jun 2025
10
Countries hit
top United States · 101

At a glance

Status
inactive
Aliases
black suit
First seen
3 years ago
Last activity
1 year ago
Onion sites
2 known endpoints
Primary sector
Business Services · 43 hits

About

Blacksuit is a financially motivated ransomware group that emerged in June 2023, quickly establishing itself as a significant threat with 184 documented victims across multiple sectors. The group's origin and specific affiliations remain largely undocumented in public threat intelligence reports, though their operational patterns suggest they operate as an independent entity rather than a traditional RaaS model. Blacksuit primarily targets organizations through common initial access vectors and employs standard ransomware deployment techniques, though detailed technical analysis of their specific encryption methods and whether they consistently employ double extortion tactics has not been widely published by major security firms. The group has demonstrated a clear preference for targeting business services, healthcare, government, and manufacturing sectors, with their victims predominantly located in English-speaking countries including the United States, United Kingdom, and Canada, as well as Spain and Germany. As of current reporting, Blacksuit remains an active ransomware operation with no publicly documented law enforcement disruptions or significant rebranding efforts.

References

6 links

External sources curated by the MISP threat-intel community.

Timeline

22 months
2023-06-01T00:00:00+00:00 · 32023-07-01T00:00:00+00:00 · 22023-09-01T00:00:00+00:00 · 12023-10-01T00:00:00+00:00 · 22023-11-01T00:00:00+00:00 · 62023-12-01T00:00:00+00:00 · 52024-01-01T00:00:00+00:00 · 42024-02-01T00:00:00+00:00 · 52024-03-01T00:00:00+00:00 · 82024-04-01T00:00:00+00:00 · 242024-05-01T00:00:00+00:00 · 182024-06-01T00:00:00+00:00 · 182024-07-01T00:00:00+00:00 · 122024-08-01T00:00:00+00:00 · 162024-09-01T00:00:00+00:00 · 102024-10-01T00:00:00+00:00 · 182024-11-01T00:00:00+00:00 · 212024-12-01T00:00:00+00:00 · 22025-03-01T00:00:00+00:00 · 22025-04-01T00:00:00+00:00 · 32025-05-01T00:00:00+00:00 · 32025-06-01T00:00:00+00:00 · 1
2023-06-01T00:00:00+00:002025-06-01T00:00:00+00:00

Top countries

🇺🇸 United States
101
🇬🇧 United Kingdom
9
🇨🇦 Canada
6
🇪🇸 Spain
4
🇩🇪 Germany
3
🇮🇹 Italy
3
🇮🇳 India
3
🇨🇭 Switzerland
3

Top sectors

Business Services
43
Healthcare
22
Government
21
Manufacturing
19
Technology
13
Transportation/Logistics
9
Education
8
Agriculture and Food Production
5

MITRE ATT&CK

10 techniques · 8 tactics

Tactics

Initial AccessExecutionDefense EvasionDiscoveryLateral MovementCollectionExfiltrationImpact

Techniques

  • T1566Phishing
  • T1190Exploit Public-Facing Application
  • T1059Command and Scripting Interpreter
  • T1562Impair Defenses
  • T1082System Information Discovery
  • T1083File and Directory Discovery
  • T1021Remote Services
  • T1560Archive Collected Data
  • T1041Exfiltration Over C2 Channel
  • T1486Data Encrypted for Impact

Recent victims

Loading…

Onion infrastructure

2 known
  • http://weg7sdx54bevnvulapqu6bpzwztryeflq3s23tegbmnhkbpqz637f2yd.onion
  • http://c7jpc6h2ccrdwmhofuij7kz6sr2fg2ndtbvvqy4fse23cf7m2e5hvqid.onion

Source

Updated 1 year ago

Data on this page is sourced from the group's own leak posts, cross-checked with public ransomware trackers (RansomLook, ransomware.live, RansomWatch), MITRE ATT&CK, and our own Tor and Telegram crawlers. This is a public observatory page — share freely.

Get alerted the next time Blacksuit posts a victim.

Add Blacksuit to your watchlist — Pro pings you within 5 minutes of any new Blacksuit leak-site post, Telegram callout, or affiliate-rebrand inference.