← All actors

BlackSuit

Aliases: Royal, Royal ransomware, BlackSuit ransomware

Source profile review date: 2026-06-21

Added to the source registry: 2023-06-12 · Source snapshot: 2026-09-15

Source metadata is not independently verified. The registry date is not necessarily the first attack date. Source synopses are translated automatically where needed; the feed may contain outdated assessments.

Research status: Existing researched dossier

Executive summary

BlackSuit is the successor or rebrand line around Royal and remains relevant through enterprise attacks, callback phishing, RDP, data exfiltration and high impact on healthcare and critical sectors.

BlackSuit/Royal is an experienced ransomware cluster with Conti heritage, double extortion, high ransom demands and public CISA/FBI advisories. Despite disruption activity, the TTPs remain important for defence.

Latest five known victim claims

Loading stored claims…

    These are public claims attributed to the group, not independently confirmed breaches. Dates indicate publication or discovery, not necessarily the attack date.

    Executive summary

    BlackSuit should be treated as a continuation of an experienced ransomware line around Royal. The group is relevant because it affects enterprise environments where identity, remote access, data and recovery are tightly connected. The name may change, but the attack chain remains recognisable: access, privilege escalation, lateral movement, data theft and encryption.

    CISA/FBI advisories around Royal/BlackSuit describe phishing, callback phishing, RDP, access brokers and public-facing applications as access routes. For organisations the risk is concrete: if external access and privileged accounts are not tightly managed, an experienced operator can quickly move toward domain-wide impact.

    Even after disruptions or takedowns, the profile remains valuable. Ransomware groups rarely disappear cleanly; affiliates, code, data and methods flow into successors. BlackSuit is therefore a defensive dossier for both the specific name and the broader Royal/Conti heritage.

    Group and development

    Royal emerged after the Conti period and became one of the visible enterprise ransomware groups. BlackSuit was later mentioned in advisories and analysis as a possible rebrand or successor line. The group targeted sectors such as healthcare, manufacturing, education, government and critical services.

    BlackSuit is known for double extortion: data is stolen and systems are encrypted. Ransom demands can be high because the group chooses organisations where downtime and data leaks cause serious damage.

    In 2025, disruptions and seizures around BlackSuit infrastructure were reported. That does not reduce the value of the profile; takedowns often lead to rebrands, affiliate shifts and reuse of methods.

    Methods and attack chain

    Initial access can occur through phishing, callback phishing, RDP, vulnerable public-facing applications or purchased credentials. Callback phishing matters because victims can be socially engineered into installing remote tools or malware.

    After access come discovery and privilege escalation. Look for domain enumeration, credential dumping, lateral movement over RDP, remote service creation, PsExec-like behaviour, PowerShell, security-tool impairment and access to backup environments.

    BlackSuit/Royal-like attacks create pressure through data theft and encryption. Data may be staged on servers, compressed and then exfiltrated. Files are then encrypted and pressure is built through communication or leak-site activity.

    Investigation must always determine whether backups, hypervisors and storage administration were accessed. With enterprise ransomware, recovery is reliable only when identity, privileged accounts and recovery platforms have been cleaned.

    Known IOCs and artefacts

    Artefacts include Royal/BlackSuit ransom notes, encrypted files, leak-site claims, phishing or callback lures, RDP logins, remote tools, service changes, vssadmin/wbadmin/bcdedit-like impact preparation and data staging.

    CISA advisories contain TTPs and IOCs that are mainly useful for retro-hunting. For current defence, behavioural indicators matter more: initial access, credential use, lateral movement, EDR tampering, exfiltration and backup impact.

    For a BlackSuit claim, check whether the data is new, whether encryption really occurred and whether rebrand or successor activity is involved. The name alone is not enough evidence.

    Victim pattern and lessons

    Royal/BlackSuit affected many organisations in public reporting, including healthcare, manufacturing, education, research, construction and critical infrastructure. Selection is driven by impact and payment pressure.

    The lesson is that large organisations remain vulnerable when helpdesk processes, remote access and privileged accounts are not tight. An experienced operator needs only one credible entry point.

    A second lesson is that takedowns do not mean the threat is gone. Controls must be aligned to TTPs, not to brand stability.

    How to defend

    Protect remote access and helpdesk processes. MFA, caller verification, remote-tool allowlisting, RDP restriction and logging of support actions are essential.

    Hunt for lateral movement and privilege use. RDP between servers, new local admins, service creation, PowerShell, credential dumping and security service stops must be correlated.

    Make recovery independent from the domain. Backup administration, hypervisors, storage and emergency accounts must be separated and tested periodically.

    Specific hunts

    For BlackSuit/Royal, hunt for callback phishing and remote support. Look for phone-based incidents, installation of remote tools, new downloads, user-context processes and subsequent privilege escalation or lateral movement.

    Check RDP and VPN traces. Royal/BlackSuit-like intrusions can start through phishing, RDP, access brokers or vulnerable applications. Look for accounts that first enter interactively and then use server or administrator privileges.

    Hunt for enterprise impact: domain admin changes, GPO changes, service creation, PsExec-like behaviour, security-tool impairment, data staging and backup-console access. The group becomes dangerous when it understands recovery resources.

    Exposure and prevention

    Exposure must include helpdesk and remote-support processes. A callback-phishing route is not solved by mail filtering alone. Check who may install remote tools, who validates support requests and how suspicious calls are reported.

    Restrict RDP and admin routes. Administration should go through jump hosts and PAM, not directly between arbitrary servers. Local admin rights must be rotated and logged.

    Separate backup and identity from daily administration accounts. BlackSuit/Royal-like attacks become much more serious when domain admins also manage recovery platforms.

    Sources and uncertainty

    BlackSuit has a strong public source base through CISA/FBI advisories and takedown reporting. The relationship with Royal is relevant, but should be used as cluster context.

    After takedowns, successors or copycats can use the same TTPs. A BlackSuit profile therefore remains valuable as a TTP profile even when infrastructure has been disrupted.

    Claims should state whether they concern Royal, BlackSuit, a successor or a reused dataset. That prevents confusion for customers and analysts.

    Scenario for leadership and SOC

    A BlackSuit/Royal scenario can begin with callback phishing. An employee calls a number, installs remote software and gives the actor a credible foothold. Credentials and lateral movement follow.

    The SOC must therefore log remote support and helpdesk processes. Which tools started, by whom, from which ticket, with which approval and which data was accessed afterwards?

    For leadership, the impact is often enterprise-wide. BlackSuit is not only an endpoint problem; it affects identity, backups, communication, customers and continuity.

    What the visitor should check concretely

    Check resilience against callback phishing. Is there a procedure that lets employees verify external support requests without using the number in the email?

    Check RDP and remote tools. Allow only approved tools, record sessions and block installation by ordinary users.

    Check whether privileged accounts are tiered. Domain admins must not be used for daily tasks, backup administration or ordinary server logins.

    Relationship with Amuneth Exposure

    For BlackSuit, Exposure must show how an external entry point can grow into enterprise impact. An open remote service is not isolated; it is a route to identity and recovery.

    Reports should therefore prioritise findings that enable access to management layers: RDP, VPN, admin panels, outdated appliances and weak authentication.

    The value for customers is that they can see before an incident which route an experienced ransomware operator is likely to choose.

    Additional defensive notes

    BlackSuit/Royal is especially dangerous because of experience. The actor does not rely on one trick, but combines social entry, remote access, privilege escalation and pressure on recovery. Defence must therefore also be chain-oriented.

    Check whether helpdesk staff have a script for suspicious callback or remote-support requests. They should not have to decide alone whether a caller is legitimate. A fixed verification route prevents improvisation under pressure.

    Create a list of systems that may never be accessed through ordinary remote support: domain controllers, backup servers, hypervisors, EDR management and storage administration. That boundary must be technically enforced.

    Additional operational questions

    For BlackSuit, determine whether social engineering can become a technical bypass. If an employee may install a remote tool over the phone, helpdesk security becomes part of the ransomware chain.

    Check whether EDR tampering is centrally reported. An experienced operator will try to stop security tools or weaken policies. If such action is visible only locally, the warning comes too late.

    Create a recovery order that handles identity first. Restoring servers without account rotation, token revocation and privileged-group review can allow the actor to return.

    Indicators of compromise (IOCs)

    Indicators are historical observations, not proof of a current infection. Validate source, age and context before hunting or blocking; legitimate administrative tools can produce false positives.

    TypeValueSourceContext
    relationshipRoyal to BlackSuit rebrand or successor relationshipCISA/FBI advisory and public reportingGebruik als clusteranalyse, niet als enig bewijs in incidenten.
    techniquephishing, callback phishing, RDP and public-facing application accessCISA/FBI Royal/BlackSuit reportingBelangrijke toegangsroutes.
    behaviordouble extortion with enterprise impactpublic advisoriesData en downtime tegelijk.

    Sources

    Evidence and limitations

    Attribution describes the source assessment, not a verified identity. A leak-site listing alone does not prove encryption, data theft, a particular vulnerability or an affiliate relationship. Missing information is left explicit.