BlackMatter is a financially motivated ransomware-as-a-service operation that emerged in July 2021, positioning itself as a successor to the defunct DarkSide and REvil ransomware groups. The group is believed to operate from Russia or former Soviet states, recruiting Russian-speaking affiliates through underground forums and operating under the RaaS model where core developers provide ransomware tools to affiliate operators in exchange for a percentage of ransom payments. BlackMatter employs sophisticated attack methodologies including initial access through compromised VPN credentials, phishing campaigns, and exploitation of known vulnerabilities, followed by deployment of custom tools for lateral movement and credential harvesting before deploying their ransomware payload that uses a combination of RSA and Salsa20 encryption algorithms, while also implementing double extortion tactics by exfiltrating sensitive data prior to encryption and threatening public release if ransom demands are not met. Notable campaigns include attacks against critical infrastructure sectors particularly targeting agricultural cooperatives, technology companies, and financial institutions across the United States, Germany, and the United Kingdom, with ransom demands reportedly ranging from hundreds of thousands to millions of dollars. The group announced their dissolution in November 2021, claiming to cease operations due to pressure from law enforcement and government agencies, though security researchers believe the core operators likely transitioned to other ransomware variants or rebranded under different names. The group has been linked to 32 public disclosures across our corpus. First observed on a leak site on September 8, 2021; most recent post November 4, 2021. The operation is currently inactive.
Also tracked as: Darkside.
Sector and geography
This disclosure adds to ransomware activity in the Food & Agriculture sector, which has 13 disclosures indexed across all operators we track. Geographically, Jobbers Meat Packing Co., Inc. is reported in United States, a country with 7,392 ransomware disclosures in our corpus.
How we know this. Darkfield monitors public ransomware leak sites continuously, archiving every new disclosure and the data later released against the victim. Each entry on this page is sourced from the operator's own publication and cross-checked against complementary OSINT feeds (RansomLook, ransomware.live, RansomWatch). We do not collect or host stolen data — only the metadata, timestamps and screenshots needed to make the public disclosure searchable and accountable. Records here are corrected when the original post is edited, retracted, or merged with another disclosure.