โ BlackSuit¶
Threat-actor battle card ยท maintained from public sources ยท last updated 2026-08-27 ยท also known as Royal (prior brand)
Overview¶
BlackSuit is the operational rebrand of the Royal ransomware group, which itself was believed to incorporate former members of the Conti ransomware operation. Royal was active from approximately September 2022 through June 2023, at which point the group transitioned to the BlackSuit brand with enhanced capabilities. The FBI and CISA updated their joint advisory (AA23-061A) on August 7, 2024 to reflect the rebrand and publish current IOCs. As of the advisory update, BlackSuit actors had collectively demanded over $500 million in ransom across hundreds of victims, with the largest individual demand reaching $60 million. The group operates a Tor-hosted data-leak site where victim data is published after ransom deadlines are missed. BlackSuit is classified as a ransomware-as-a-service (RaaS) operation with affiliates conducting intrusions while operators manage infrastructure and negotiation.
Tradecraft¶
- Initial access: Phishing emails are the primary documented vector; also uses malicious advertisements, fake software updates, and exploitation of public-facing applications. Purchases access from initial-access brokers (IABs) in some intrusions.
- Defense evasion: Disables antivirus and endpoint-security software early in the intrusion using legitimate tools and scripts before deploying the encryptor.
- Data exfiltration: Exfiltrates large volumes of data prior to encryption to support double-extortion pressure; uses legitimate cloud storage services as staging.
- Encryption: Partial-file encryption (encrypts a configurable percentage of each file) to maximize speed while preserving enough data for the victim to confirm the attack is real. Cross-platform capability: Windows and Linux/ESXi variants confirmed.
- Ransom demands: Typically $1Mโ$10M, determined by victim size and revenue; largest confirmed single demand: $60M. Payments demanded in Bitcoin. Negotiation conducted via Tor-hosted chat.
- Double extortion: Data published on BlackSuit leak site if ransom deadline is missed; threat of timed public release used as leverage throughout negotiation.
Notable victims¶
- CDK Global (US, automotive software, June 2024) โ Provider of dealership-management software to 15,000+ US auto dealerships; sustained disruption to vehicle sales and service operations across the country; approximately $25M ransom reportedly paid; one of the highest-impact RaaS attacks of 2024 by economic reach
- Kootenai Health (US, healthcare) โ Patient data compromised; one of several healthcare orgs in the portfolio
- Kansas City Area Transportation Authority (US, public transport)
- Numerous schools, municipal governments, and critical manufacturing organisations across the US and Western Europe
Assessment¶
BlackSuit's infrastructure was disrupted July 24, 2025 in Operation Checkmate, a coordinated international law enforcement action involving the FBI, DoJ, UK NCA, Cyber Police of Ukraine, Europol, and German LKA. Four servers and nine domains were seized; $1.09M in cryptocurrency was confiscated. At the time of disruption, BlackSuit actors had collectively demanded over $500M across 450+ US victims. The group had been preparing a rebrand to Chaos RaaS (first appeared February 2025) before the takedown attracted too much attention to the venture. Cisco Talos assesses with moderate confidence that Chaos was formed by former BlackSuit members, based on shared encryption methodology, ransom note structure, and tooling. The Royal-to-BlackSuit-to-Chaos lineage is the same operator group cycling through brands to shed law-enforcement pressure โ a now well-established playbook among high-volume RaaS operators.
Chaos RaaS (August 2026 update): As of August 2026, Chaos has 56+ claimed victims across 13 countries: US dominant (56 victims), followed by Canada (4), Germany (4), UK, New Zealand, and India. The group expanded its attack chain in early 2026 with a Microsoft Teams vishing campaign (FebโJun 2026): operators flood targets with spam, then impersonate IT security staff via Teams to coerce victims into granting Microsoft Quick Assist remote access before deploying ransomware. The vishing variant was profiled by Sophos (Jul 2026) and Cisco Talos. July 2026: Chaos claimed Sleeman Breweries (Sapporo Holdings Canadian subsidiary, 420 GB alleged; June 24 incident initially unattributed). Beyond double-extortion, Chaos employs triple extortion โ threatening DDoS โ and quadruple extortion via direct contact with the victim's customers or competitors. Rapid7 analysts flag a possible Iran/MuddyWater overlap in some Chaos activity, suggesting the brand may be used opportunistically to mask state-sponsored espionage โ attribution remains contested. Organizations should track the Chaos RaaS brand as the operational successor and treat CISA/FBI advisory AA23-061A (August 2024) as the authoritative historical IOC and TTP reference.
Sources¶
- CISA/FBI Joint Advisory AA23-061A โ #StopRansomware: BlackSuit (Royal) Ransomware (updated August 7, 2024)
- CISA Alert โ Royal Ransomware Actors Rebrand as "BlackSuit," FBI and CISA Release Update to Advisory (August 7, 2024)
- DOJ โ Justice Department Announces Coordinated Disruption Actions Against BlackSuit (Royal) Ransomware Operations (August 11, 2025)
- The Hacker News โ Chaos RaaS Emerges After BlackSuit Takedown, Demanding $300K from U.S. Victims
- SecurityWeek โ BlackSuit Ransomware Group Transitioning to 'Chaos' Amid Leak Site Seizure
- BankInfoSecurity โ Rise of Chaos Ransomware Tied to BlackSuit Group's Exit
- Industrial Cyber โ DHS, global partners dismantle BlackSuit ransomware network after 450 US victims
- The Record โ Royal ransomware successor BlackSuit has demanded more than $500 million
- HIPAA Journal โ CISA, FBI Issue Updated Warning Confirming Royal Ransomware Has Rebranded as BlackSuit
- Darktrace โ From Royal to BlackSuit: Understanding the Tactics and Impact of a Sophisticated Ransomware Strain
- Security Boulevard โ Chaos Ransomware: BlackSuit-Linked RaaS Resurgence and Detection Opportunities (July 2026)
- Rapid7 โ Muddying the Tracks: The State-Sponsored Shadow Behind Chaos Ransomware
- ExtraHop โ CHAOS in a BLACKSUIT: Triple Extortion Ransomware
- Sophos โ Chaos in Teams vishing (July 2026)
- AttackIQ โ Chaos Ransomware: RaaS Resurgence and Detection (July 2026)
๐๏ธ Attacks & victims¶
All disclosed victims attributed to this actor, newest first.
No attacks recorded yet.