BlackSuit Ransom Gang Taken Down

Over $370 million worth of crypto-currency assets stolen by or on behalf of the notorious Russian linked BlackSuit ransomware gang earlier known as Royal, were seized ahead of a multi-national takedown operation, led by US law enforcement. 

The BlackSuit group shut down the city of Dallas and successfully attacked more than 450 entities in the US since emerging in 2022. Now, the ransomware gang’s darknet extortion sites have been seized in an operation involving police from more than nine countries including Germany, France and the United Kingdom.  

A splash page replaced the gang’s list of victims on its main TOR domain as well as its private negotiation pages, stating these sites were “seized by US Homeland Security Investigations (HSI)” as part of a coordinated international operation.  The US Justice Department has confirmed the disruption and website seizure, but kept the warrant for the action sealed.  

The statements are the first recognition from US agencies of the operation. German officials confirmed the operation last week, noting that they confiscated technical infrastructure used by the group. “Substantial amounts of data were secured, which are now being analyzed to investigate and identify other perpetrators,” German law enforcement sources said.  

The FBI said in 2024 that the group demanded more than $500 million in ransoms and after the rebrand continued to issue exorbitant ransom demands, some of which reached as high as $60 million. 

BlackSuit also took responsibility for dozens of attacks on US schools and colleges and companies and local governments, including the Japanese medallion giant Kadokawa and Tampa Bay Zoo. In April 2024, the gang claimed responsibility for an attack against the blood plasma collection organisation Octapharma, which the American Hospital Association said “resulted in the temporary closure of almost 200 blood plasma collection centers” across the country. 

US Secret Service Criminal Investigative Division Special Agent in Charge William Mancino said the takedown was a “critical blow to BlackSuit’s infrastructure and operations.” 

This takedown was part of Operation Checkmate, a Europol-led initiative targeting the Royal and BlackSuit ransomware operations. Cyber security firm Bitdefender assisted the agencies in the operation and said it was “another important milestone in the fight against organised cybercrime.” 

Following these events, it is understood that BlackSuit  has already pivoted to forming a new ransomware operation called Chaos. 

The DOJ has recently said that it seized $2.4 million worth of crypto-currency from a crypto-currency address allegedly associated with a member of the Chaos ransomware group, known as “Hors”, which they said has been tied to ransomware attacks against victims located in Texas and elsewhere.

The Record   |  SC Media     |   Sunday World   |   Presse Portal  |  American Hospital Association     |     ICE     

US Dept of Justice  |  Computer Weekly    |     Mondaq

Image: Unsplash

You Might Also Read: 

Scattered Spider Attacks - Four Arrested:


If you like this website and use the comprehensive 8,000-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible

« The Urgent Need For Crypto Agility
Sprawling Non-Human Identities Are the Next Big Cyber Risk »

ManageEngine
CyberSecurity Jobsite
Check Point

Directory of Suppliers

NordLayer

NordLayer

NordLayer is an adaptive network access security solution for modern businesses — from the world’s most trusted cybersecurity brand, Nord Security. 

Authentic8

Authentic8

Authentic8 transforms how organizations secure and control the use of the web with Silo, its patented cloud browser.

CYRIN

CYRIN

CYRIN® Cyber Range. Real Tools, Real Attacks, Real Scenarios. See why leading educational institutions and companies in the U.S. have begun to adopt the CYRIN® system.

North Infosec Testing (North IT)

North Infosec Testing (North IT)

North IT (North Infosec Testing) are an award-winning provider of web, software, and application penetration testing.

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

NESEC

NESEC

NESEC is a specialist in information security consulting services and solutions.

Niksun

Niksun

Niksun's forensics-based cyber security and network performance monitoring products provide customers with actionable insight into security threats, performance issues, and compliance risks.

AimBrain

AimBrain

AimBrain tools detect and prevent fraud, faster and more accurately than ever before.

MagicCube

MagicCube

MagicCube is a device independent IoT security platform that protects against on-device, cloud, and network attacks.

DestructData

DestructData

DestructData is a leading independent provider of End of Life data destruction/security solutions.

DarkLight

DarkLight

DarkLight Cyio is an AI-powered cyber risk solution that applies real-time threat intelligence and business context to risk prioritization.

Sequretek

Sequretek

Sequretek was formed with the aim to “Simplify Security”. We envision a future where enterprise networks are streamlined, secure and simple.

Variti

Variti

Variti Intelligent Active Bot Protection technology — traffic analysis, detection and stopping of malicious bots in real-time and effective response to DDoS attacks.

Ampliphae

Ampliphae

Ampliphae gives you an easy-to-deploy, sophisticated and affordable cloud-discovery, security and compliance platform.

Syndis

Syndis

Syndis is a leading information security company helping to defend organizations by providing bespoke services and innovative security solutions in the global market.

ditno

ditno

ditno uses machine learning to help you build a fully governed and micro-segmented network. Dramatically mitigate risk and prevent lateral movement across your organisation – all from one centralised

Riskaware

Riskaware

CyberAware, by Riskaware, provides business-critical cyber attack analysis and impact assessments using NIST standards aligned with NCSC guidance.

MoogleLabs

MoogleLabs

MoogleLabs leverage AI/ML, Blockchain, DevOps, and Data Science to come up with the best solutions for diverse businesses.

Eclypses

Eclypses

Eclypses has a disrupting cyber technology, offering organizations an advanced data security solution called MicroToken Exchange (MTE).

BUI

BUI

BUI is a global technology consultancy and Cloud Solution Provider specialising in cloud, security, and networking solutions for mid-market and enterprise-level business across the world.

Sailo Technologies

Sailo Technologies

Sailo.Technologies is a revolutionary company in Blockchain security, integrating advanced cryptographic technologies to defend transactions and digital assets.