Skip to content

โ€” BlackSuit

Threat-actor battle card ยท maintained from public sources ยท last updated 2026-08-27 ยท also known as Royal (prior brand)

CategoryRansomware-as-a-Service
AttributionUnknown; financially motivated; likely Eastern European; not officially attributed to a nation-state; believed to include former Conti members
First seenJune 2023 (as BlackSuit; predecessor Royal active September 2022 โ€“ June 2023)
StatusDisrupted (Operation Checkmate, July 2025); operators assessed to have rebranded as Chaos RaaS
Victims L3Mโ€”
Victims YTDโ€”
Primary targetsHealthcare, Government, Education, Critical Manufacturing, Commercial Facilities, Critical Infrastructure

Overview

BlackSuit is the operational rebrand of the Royal ransomware group, which itself was believed to incorporate former members of the Conti ransomware operation. Royal was active from approximately September 2022 through June 2023, at which point the group transitioned to the BlackSuit brand with enhanced capabilities. The FBI and CISA updated their joint advisory (AA23-061A) on August 7, 2024 to reflect the rebrand and publish current IOCs. As of the advisory update, BlackSuit actors had collectively demanded over $500 million in ransom across hundreds of victims, with the largest individual demand reaching $60 million. The group operates a Tor-hosted data-leak site where victim data is published after ransom deadlines are missed. BlackSuit is classified as a ransomware-as-a-service (RaaS) operation with affiliates conducting intrusions while operators manage infrastructure and negotiation.

Tradecraft

  • Initial access: Phishing emails are the primary documented vector; also uses malicious advertisements, fake software updates, and exploitation of public-facing applications. Purchases access from initial-access brokers (IABs) in some intrusions.
  • Defense evasion: Disables antivirus and endpoint-security software early in the intrusion using legitimate tools and scripts before deploying the encryptor.
  • Data exfiltration: Exfiltrates large volumes of data prior to encryption to support double-extortion pressure; uses legitimate cloud storage services as staging.
  • Encryption: Partial-file encryption (encrypts a configurable percentage of each file) to maximize speed while preserving enough data for the victim to confirm the attack is real. Cross-platform capability: Windows and Linux/ESXi variants confirmed.
  • Ransom demands: Typically $1Mโ€“$10M, determined by victim size and revenue; largest confirmed single demand: $60M. Payments demanded in Bitcoin. Negotiation conducted via Tor-hosted chat.
  • Double extortion: Data published on BlackSuit leak site if ransom deadline is missed; threat of timed public release used as leverage throughout negotiation.

Notable victims

  • CDK Global (US, automotive software, June 2024) โ€” Provider of dealership-management software to 15,000+ US auto dealerships; sustained disruption to vehicle sales and service operations across the country; approximately $25M ransom reportedly paid; one of the highest-impact RaaS attacks of 2024 by economic reach
  • Kootenai Health (US, healthcare) โ€” Patient data compromised; one of several healthcare orgs in the portfolio
  • Kansas City Area Transportation Authority (US, public transport)
  • Numerous schools, municipal governments, and critical manufacturing organisations across the US and Western Europe

Assessment

BlackSuit's infrastructure was disrupted July 24, 2025 in Operation Checkmate, a coordinated international law enforcement action involving the FBI, DoJ, UK NCA, Cyber Police of Ukraine, Europol, and German LKA. Four servers and nine domains were seized; $1.09M in cryptocurrency was confiscated. At the time of disruption, BlackSuit actors had collectively demanded over $500M across 450+ US victims. The group had been preparing a rebrand to Chaos RaaS (first appeared February 2025) before the takedown attracted too much attention to the venture. Cisco Talos assesses with moderate confidence that Chaos was formed by former BlackSuit members, based on shared encryption methodology, ransom note structure, and tooling. The Royal-to-BlackSuit-to-Chaos lineage is the same operator group cycling through brands to shed law-enforcement pressure โ€” a now well-established playbook among high-volume RaaS operators.

Chaos RaaS (August 2026 update): As of August 2026, Chaos has 56+ claimed victims across 13 countries: US dominant (56 victims), followed by Canada (4), Germany (4), UK, New Zealand, and India. The group expanded its attack chain in early 2026 with a Microsoft Teams vishing campaign (Febโ€“Jun 2026): operators flood targets with spam, then impersonate IT security staff via Teams to coerce victims into granting Microsoft Quick Assist remote access before deploying ransomware. The vishing variant was profiled by Sophos (Jul 2026) and Cisco Talos. July 2026: Chaos claimed Sleeman Breweries (Sapporo Holdings Canadian subsidiary, 420 GB alleged; June 24 incident initially unattributed). Beyond double-extortion, Chaos employs triple extortion โ€” threatening DDoS โ€” and quadruple extortion via direct contact with the victim's customers or competitors. Rapid7 analysts flag a possible Iran/MuddyWater overlap in some Chaos activity, suggesting the brand may be used opportunistically to mask state-sponsored espionage โ€” attribution remains contested. Organizations should track the Chaos RaaS brand as the operational successor and treat CISA/FBI advisory AA23-061A (August 2024) as the authoritative historical IOC and TTP reference.

Sources

๐Ÿ—‚๏ธ Attacks & victims

All disclosed victims attributed to this actor, newest first.

No attacks recorded yet.


โ† All threat actors ยท Full victim database โ†’