{"investigation":{"slug":"blacksuit","entity_name":"BlackSuit","trust_score":0,"severity_base":null,"score_modifier":0,"confidence":1,"status":"published","content_type":"investigation","summary":"BlackSuit is a ransomware-as-a-service (RaaS) operation that emerged in May 2023 as a rebranding of the Royal ransomware gang, itself a successor to the Conti cybercrime syndicate believed to be operated by Russian-speaking threat actors. The group employed double-extortion tactics across critical infrastructure sectors including healthcare, automotive, education, and government, compromising over 450 U.S. victims and demanding more than $500 million in ransom, primarily in Bitcoin, before international law enforcement dismantled its infrastructure in July 2025 under Operation Checkmate.","sections":[{"content":"BlackSuit is assessed by FBI, CISA, and multiple cybersecurity researchers to be a direct evolution of the Royal ransomware operation, which itself emerged from the Conti ransomware syndicate after Conti's public implosion in mid-2022 following a major internal data leak. The lineage traces through at least six operational identities over eight years: Conti → Quantum → Royal → BlackSuit, with BlackSuit first observed by security researchers in May 2023. CISA and the FBI confirmed the Royal-to-BlackSuit rebrand in an August 7, 2024 advisory update, noting that BlackSuit ransomware 'shares a number of identified coding characteristics similar to Royal.' The group is assessed with high confidence to be composed of Russian-speaking threat actors who promoted their affiliate RaaS platform on Russian-language cybercriminal forums on the dark web. German law enforcement identified at least 184 BlackSuit-specific victims separately from the broader Royal-era victim pool.","heading":"Origins and Criminal Lineage","sources":[],"severity":"medium"},{"content":"Since the Royal ransomware group began operating in approximately September 2022 through the BlackSuit rebranding, the combined operation compromised over 450 known victims in the United States alone. Targeted sectors included healthcare, education, government, energy, public safety, manufacturing, and automotive. CISA reported that aggregate extortion demands surpassed $500 million by August 2024, while confirmed ransom payments to the group totaled more than $370 million. Individual ransom demands typically ranged from $1 million to $10 million in Bitcoin, with the largest single demand documented at $60 million. By 2024, BlackSuit had logged at least 93 confirmed victims on its data-leak site, with activity peaking at 10 published victims in a single month (May 2024). Activity on the leak site increased sharply in Q1 2024, with more BlackSuit incidents recorded in February 2024 alone than in all of 2023.","heading":"Scale of Operations and Victim Impact","sources":[],"severity":"medium"},{"content":"In June 2024, BlackSuit executed a high-profile ransomware attack against CDK Global, a software-as-a-service provider whose dealer management systems are used by approximately 15,000 automotive dealerships across North America. The initial intrusion was detected on or around June 18, 2024, and a secondary attack occurred on June 19 during recovery efforts. The disruption forced dealerships to revert to manual processes for nearly two weeks, with some groups not regaining system access until June 28. Multiple publicly traded dealership groups — including Lithia Motors, Group 1 Automotive, Penske Automotive Group, and Sonic Automotive — filed disclosures with the U.S. Securities and Exchange Commission regarding the disruption. Bloomberg reported the initial ransom demand was approximately $10 million, which BlackSuit subsequently raised to over $50 million. On-chain analysis by CyberScoop identified a cryptocurrency wallet likely controlled by BlackSuit receiving approximately 387 Bitcoin (worth roughly $25 million) on June 21, 2024, two days after the attack began. CNN Business reported CDK almost certainly paid a $25 million ransom. Anderson Economic Group estimated the aggregate cost to dealerships exceeded $1 billion.","heading":"CDK Global Attack (June 2024)","sources":[],"severity":"medium"},{"content":"BlackSuit has demonstrated a persistent pattern of targeting healthcare entities in violation of broadly observed norms around critical-infrastructure attacks. In April 2024, BlackSuit claimed responsibility for an attack on Octapharma Plasma, forcing the temporary closure of more than 160 blood plasma donation centers across the United States. The attack exploited vulnerabilities in Octapharma's VMware systems and resulted in the confirmed exposure of sensitive personal data including names, Social Security numbers, health information, and financial records. A $2.55 million class-action settlement was later reached. Additional confirmed or claimed healthcare victims include South Africa's National Health Laboratory Service, Revenetics, and Morris Hospital and Healthcare Centers. The group also allegedly struck an unnamed organization providing medical imaging and radiology services to nearly 1,000 U.S. hospitals, forcing that entity to shut down computer systems and turn away patients. The U.S. Department of Health and Human Services issued a sector-specific alert to healthcare organizations in November 2023 warning of BlackSuit's targeting patterns. The American Hospital Association amplified the FBI/CISA advisory update in August 2024.","heading":"Healthcare and Critical Infrastructure Targeting","sources":[],"severity":"medium"},{"content":"BlackSuit exclusively demanded ransom payments in Bitcoin (BTC), directing victims to specialized darknet websites where wallet addresses were communicated. To obscure the money trail, operators moved funds repeatedly across virtual currency exchange accounts, employing layering techniques consistent with professional money-laundering tradecraft. U.S. authorities tracked one specific payment: on or about April 4, 2023, a victim paid 49.3120227 BTC (valued at approximately $1,445,454 at the time) to decrypt their files. The CDK Global attack resulted in an on-chain-confirmed payment of approximately 387 BTC (~$25 million) to a wallet assessed to be controlled by BlackSuit. Across the full Royal-and-BlackSuit operational period, confirmed ransom receipts exceeded $370 million in cryptocurrency. ZachXBT, the pseudonymous on-chain investigator, flagged BlackSuit's operations in connection with broader crypto-enabled ransomware extortion activity.","heading":"Cryptocurrency Use and Financial Flows","sources":[],"severity":"medium"},{"content":"BlackSuit employs a multistage attack methodology documented in detail by the FBI, CISA, and multiple private threat intelligence firms. Initial access is most commonly achieved via phishing emails, though the group also exploits exposed Remote Desktop Protocol (RDP) endpoints. Following initial access, operators conduct Kerberoasting to harvest service account credentials, use PsExec for lateral movement, and exfiltrate data prior to encrypting files — a classic double-extortion model in which stolen data serves both as proof of compromise and ongoing leverage. The ransomware appends a '.blacksuit' extension to encrypted files and drops a ransom note titled 'readme.blacksuit.txt'. BlackSuit targets both Windows and Linux environments; the Linux variant specifically targets VMware ESXi hypervisors. The payload uses heavy obfuscation to evade detection. If victims do not pay, their stolen data is published to a Tor-hosted data-leak site. Security researchers at ReliaQuest observed Kerberoasting as the onset indicator in at least one confirmed April 2024 customer incident.","heading":"Technical Tactics, Techniques, and Procedures","sources":[],"severity":"medium"},{"content":"On July 24, 2025, U.S. and international law enforcement agencies conducted a coordinated disruption operation — designated Operation Checkmate — against BlackSuit's infrastructure under a Europol Joint Cybercrime Action Task Force (J-CAT) framework. Participating agencies included the U.S. Department of Justice, ICE Homeland Security Investigations (HSI), IRS Criminal Investigation's Cyber Crimes Unit, the U.S. Secret Service, the FBI, Europol, the UK National Crime Agency, Ukraine Cyber Police, and partners in Germany, Ireland, France, Canada, and Lithuania. The operation seized four servers, nine domains, and cryptocurrency valued at $1,091,453 at the time of confiscation. BlackSuit's darknet leak site displayed a seizure banner beginning July 24. The DOJ announced the actions publicly in August 2025. Researchers noted that much of the group had already dispersed prior to the takedown, with former members assessed to have migrated to the INC ransomware brand and, separately, to a newer group called Chaos ransomware (identified with moderate confidence as a BlackSuit successor).","heading":"Law Enforcement Action: Operation Checkmate (July 2025)","sources":[],"severity":"medium"},{"content":"BlackSuit and its Royal/Conti predecessors are assessed by U.S. intelligence and cybersecurity agencies to be Russian-speaking criminal operations. The group advertised its RaaS affiliate program on Russian-language dark web forums. Consistent with Conti-lineage groups, BlackSuit affiliates historically avoided targeting entities in Russia and former Soviet states, a behavioral pattern commonly associated with tacit tolerance by Russian authorities. No public indictments naming specific Russian nationals had been confirmed as of the time of the July 2025 takedown, and no suspects were publicly arrested as part of Operation Checkmate. The FBI and CISA have not formally attributed the group to Russian state direction, treating it as a criminal organization with a Russia nexus rather than a state-sponsored actor.","heading":"Russian Government Nexus Assessment","sources":[],"severity":"medium"}],"timeline":[{"date":"2022-05","event":"Conti ransomware syndicate publicly dissolves following a major internal data leak; members splinter into successor groups including Quantum and Zeon.","source":"","source_url":"https://blog.barracuda.com/2024/10/29/blacksuit-ransomware--8-years--6-names--1-cybercrime-syndicate","date_original":"2022-05-01"},{"date":"2022-09","event":"Royal ransomware operation begins activity, drawing membership from former Conti operators; targets U.S. critical infrastructure sectors.","source":"","source_url":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-061a","date_original":"2022-09-01"},{"date":"2023-05","event":"BlackSuit ransomware first observed by security researchers; payload shares significant code overlap with Royal ransomware.","source":"","source_url":"https://www.picussecurity.com/resource/blog/blacksuit-ransomware-group","date_original":"2023-05-01"},{"date":"2023-11-15","event":"CISA and FBI issue joint advisory warning that Royal ransomware actors are testing a potential rebrand to BlackSuit.","source":"","source_url":"https://techcrunch.com/2023/11/15/cisa-fbi-royal-ransomware-blacksuit-sanctions/"},{"date":"2024-04-17","event":"BlackSuit attacks Octapharma Plasma, forcing temporary closure of more than 160 blood plasma donation centers across the United States.","source":"","source_url":"https://therecord.media/plasma-donation-company-cyberattack-blacksuit"},{"date":"2024-06-18","event":"BlackSuit launches ransomware attack against CDK Global, disrupting dealer management systems at approximately 15,000 North American automotive dealerships.","source":"","source_url":"https://www.esentire.com/security-advisories/blacksuit-ransomware-impacts-cdk-global"},{"date":"2024-06-21","event":"On-chain analysis identifies approximately 387 Bitcoin (~$25 million) transferred to a wallet assessed to be controlled by BlackSuit, consistent with a CDK Global ransom payment.","source":"","source_url":"https://cyberscoop.com/cdk-ransom-blacksuit-25-million/"},{"date":"2024-08-07","event":"CISA and FBI release updated joint advisory formally confirming Royal ransomware actors have rebranded as BlackSuit; aggregate extortion demands reported to exceed $500 million.","source":"","source_url":"https://www.cisa.gov/news-events/alerts/2024/08/07/royal-ransomware-actors-rebrand-blacksuit-fbi-and-cisa-release-update-advisory"},{"date":"2025-07-24","event":"Operation Checkmate: U.S. DOJ, ICE HSI, FBI, Europol, and international partners seize four BlackSuit servers, nine domains, and $1,091,453 in cryptocurrency; BlackSuit's darknet leak site displays seizure banner.","source":"","source_url":"https://www.ice.gov/news/releases/ice-washington-dc-leads-international-takedown-blacksuit-ransomware-infrastructure"},{"date":"2025-08-12","event":"DOJ publicly announces Operation Checkmate results; former BlackSuit members assessed to have migrated to INC ransomware and Chaos ransomware successor groups.","source":"","source_url":"https://www.axios.com/2025/08/12/doj-blacksuit-ransomware-cryptocurrency-seizure"}],"sources_used":[],"source_tags":["zachxbt"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet","created_at":"2026-05-04T16:04:58.071488+00:00","updated_at":"2026-08-29T01:35:51.557+00:00"}}