Skip to main content
AVOID.NET

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·5QxVSA…e1fN

Summary

BlackSuit is a ransomware-as-a-service (RaaS) operation that emerged in May 2023 as a rebranding of the Royal ransomware gang, itself a successor to the Conti cybercrime syndicate believed to be operated by Russian-speaking threat actors. The group employed double-extortion tactics across critical infrastructure sectors including healthcare, automotive, education, and government, compromising over 450 U.S. victims and demanding more than $500 million in ransom, primarily in Bitcoin, before international law enforcement dismantled its infrastructure in July 2025 under Operation Checkmate.

Connected Through

2 shared actors · 490 investigations

Distinct actors this investigation shares with others — holders, traders, and named parties. Shared infrastructure (exchanges, pools) is excluded.

Have evidence about BlackSuit?

Timeline(10 events)

May 2022

Conti ransomware syndicate publicly dissolves following a major internal data leak; members splinter into successor groups including Quantum and Zeon.

September 2022

Royal ransomware operation begins activity, drawing membership from former Conti operators; targets U.S. critical infrastructure sectors.

May 2023

BlackSuit ransomware first observed by security researchers; payload shares significant code overlap with Royal ransomware.

15 November 2023

CISA and FBI issue joint advisory warning that Royal ransomware actors are testing a potential rebrand to BlackSuit.

17 April 2024

BlackSuit attacks Octapharma Plasma, forcing temporary closure of more than 160 blood plasma donation centers across the United States.

18 June 2024

BlackSuit launches ransomware attack against CDK Global, disrupting dealer management systems at approximately 15,000 North American automotive dealerships.

21 June 2024

On-chain analysis identifies approximately 387 Bitcoin (~$25 million) transferred to a wallet assessed to be controlled by BlackSuit, consistent with a CDK Global ransom payment.

7 August 2024

CISA and FBI release updated joint advisory formally confirming Royal ransomware actors have rebranded as BlackSuit; aggregate extortion demands reported to exceed $500 million.

24 July 2025

Operation Checkmate: U.S. DOJ, ICE HSI, FBI, Europol, and international partners seize four BlackSuit servers, nine domains, and $1,091,453 in cryptocurrency; BlackSuit's darknet leak site displays seizure banner.

12 August 2025

DOJ publicly announces Operation Checkmate results; former BlackSuit members assessed to have migrated to INC ransomware and Chaos ransomware successor groups.

Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (1 event).

model: claude-sonnet

generated: 5/4/2026, 4:04:58 PM

last updated: 8/29/2026, 1:35:51 AM

4 views

avoid.net — verified advice for a post-truth world