BlackSuit
Summary
BlackSuit is a ransomware-as-a-service (RaaS) operation that emerged in May 2023 as a rebranding of the Royal ransomware gang, itself a successor to the Conti cybercrime syndicate believed to be operated by Russian-speaking threat actors. The group employed double-extortion tactics across critical infrastructure sectors including healthcare, automotive, education, and government, compromising over 450 U.S. victims and demanding more than $500 million in ransom, primarily in Bitcoin, before international law enforcement dismantled its infrastructure in July 2025 under Operation Checkmate.
Connected Entities
1 entitiesTimeline(10 events)
2022-05-01
Conti ransomware syndicate publicly dissolves following a major internal data leak; members splinter into successor groups including Quantum and Zeon.
2022-09-01
Royal ransomware operation begins activity, drawing membership from former Conti operators; targets U.S. critical infrastructure sectors.
2023-05-01
BlackSuit ransomware first observed by security researchers; payload shares significant code overlap with Royal ransomware.
2023-11-15
CISA and FBI issue joint advisory warning that Royal ransomware actors are testing a potential rebrand to BlackSuit.
2024-04-17
BlackSuit attacks Octapharma Plasma, forcing temporary closure of more than 160 blood plasma donation centers across the United States.
2024-06-18
BlackSuit launches ransomware attack against CDK Global, disrupting dealer management systems at approximately 15,000 North American automotive dealerships.
2024-06-21
On-chain analysis identifies approximately 387 Bitcoin (~$25 million) transferred to a wallet assessed to be controlled by BlackSuit, consistent with a CDK Global ransom payment.
2024-08-07
CISA and FBI release updated joint advisory formally confirming Royal ransomware actors have rebranded as BlackSuit; aggregate extortion demands reported to exceed $500 million.
Decision Log
- hash: DQPuDHq2qnVwvjifaAAkxSnitQp4fR4hcEhjZXLuJqoL
This investigation is cryptographically anchored to the Solana blockchain and source URLs are archived via the Internet Archive.
model: claude-sonnet
generated: 5/4/2026, 4:04:58 PM
last updated: 5/26/2026, 4:11:14 AM
avoid.net — verified advice for a post-truth world