[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/ "High Profile Threats")
* [Ransomware](https://unit42.paloaltonetworks.com/category/ransomware/ "Ransomware")  
  [Ransomware](https://unit42.paloaltonetworks.com/category/ransomware/)

# Threat Assessment: Ignoble Scorpius, Distributors of BlackSuit Ransomware

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 16 min read  
Related Products  
[![Advanced WildFire icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced WildFire](https://unit42.paloaltonetworks.com/product-category/advanced-wildfire/ "Advanced WildFire")[![Cloud-Delivered Security Services icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Cloud-Delivered Security Services](https://unit42.paloaltonetworks.com/product-category/cloud-delivered-security-services/ "Cloud-Delivered Security Services")[![Cortex icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex](https://unit42.paloaltonetworks.com/product-category/cortex/ "Cortex")[![Cortex XDR icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XDR](https://unit42.paloaltonetworks.com/product-category/cortex-xdr/ "Cortex XDR")[![Cortex XSIAM icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XSIAM](https://unit42.paloaltonetworks.com/product-category/cortex-xsiam/ "Cortex XSIAM")[![Managed Threat Hunting icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/unit42_RGB_logo_Icon_Color.png)Managed Threat Hunting](https://unit42.paloaltonetworks.com/product-category/managed-threat-hunting/ "Managed Threat Hunting")[![Unit 42 Incident Response icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/unit42_RGB_logo_Icon_Color.png)Unit 42 Incident Response](https://unit42.paloaltonetworks.com/product-category/unit-42-incident-response/ "Unit 42 Incident Response")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Unit 42](https://unit42.paloaltonetworks.com/author/unit42/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:November 20, 2024

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Cybercrime](https://unit42.paloaltonetworks.com/category/cybercrime/)
  * [High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/)
  * [Ransomware](https://unit42.paloaltonetworks.com/category/ransomware/)
  * [Threat Actor Groups](https://unit42.paloaltonetworks.com/category/threat-actor-groups/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [BlackSuit ransomware](https://unit42.paloaltonetworks.com/tag/blacksuit-ransomware/)
  * [Construction](https://unit42.paloaltonetworks.com/tag/construction/)
  * [Education](https://unit42.paloaltonetworks.com/tag/education/)
  * [Extortion](https://unit42.paloaltonetworks.com/tag/extortion/)
  * [Ignoble Scorpius](https://unit42.paloaltonetworks.com/tag/ignoble-scorpius/)
  * [Leaksite](https://unit42.paloaltonetworks.com/tag/leaksite/)
  * [Manufacturing](https://unit42.paloaltonetworks.com/tag/manufacturing/)
  * [Royal Ransomware](https://unit42.paloaltonetworks.com/tag/royal-ransomware/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/threat-assessment-blacksuit-ransomware-ignoble-scorpius/?pdf=download&lg=en&_wpnonce=1f7a0335d5 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/threat-assessment-blacksuit-ransomware-ignoble-scorpius/?pdf=print&lg=en&_wpnonce=1f7a0335d5 "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Threat%20Assessment:%20Ignoble%20Scorpius,%20Distributors%20of%20BlackSuit%20Ransomware&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fthreat-assessment-blacksuit-ransomware-ignoble-scorpius%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fthreat-assessment-blacksuit-ransomware-ignoble-scorpius%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fthreat-assessment-blacksuit-ransomware-ignoble-scorpius%2F&title=Threat%20Assessment:%20Ignoble%20Scorpius,%20Distributors%20of%20BlackSuit%20Ransomware "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fthreat-assessment-blacksuit-ransomware-ignoble-scorpius%2F&text=Threat%20Assessment:%20Ignoble%20Scorpius,%20Distributors%20of%20BlackSuit%20Ransomware "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fthreat-assessment-blacksuit-ransomware-ignoble-scorpius%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Threat%20Assessment:%20Ignoble%20Scorpius,%20Distributors%20of%20BlackSuit%20Ransomware%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fthreat-assessment-blacksuit-ransomware-ignoble-scorpius%2F "Share in Mastodon")

## Executive Summary

Unit 42 researchers have observed an increase in BlackSuit ransomware activity beginning in March 2024 that suggests a ramp up of operations. This threat emerged as a rebrand of Royal ransomware, which occurred in May 2023. Unit 42 tracks the group behind this threat as Ignoble Scorpius. Since the rebrand, Unit 42 has observed at least **93** victims globally, a quarter of which were in the construction and manufacturing industries.

The group describes themselves as an "extortioner named BlackSuit" and claims to reverse file encryption for "quite a small compensation essentially." Although the group states the compensation is small, Unit 42 has observed that, on average, the initial ransom demand is about equal to **1.6%** of the victim organization's annual revenue. As of the date of this report, the median victim revenue across all industries is roughly **$19.5 million**, making the ransom payout quite significant for all organizations.

This threat assessment includes details identified during routine threat research activities, incident response cases and collaboration with the Unit 42 Managed Threat Hunting team.

This report maps the group's activity to the MITRE ATT\&CK® framework in [that section](#post-137574-_pa5s1ucxb5t), which organizations can use to assess their coverage of threats posed by Ignoble Scorpius, pre- and post-compromise.

Palo Alto Networks customers are better protected from the threats discussed above through the following products:

* The Unit 42 [Managed Threat Hunting](https://www.paloaltonetworks.com/unit42/respond/managed-threat-hunting) and [Managed Detection and Response](https://www.paloaltonetworks.com/resources/datasheets/unit42-managed-detection-and-response) teams conduct proactive hunts for pre- and post-incident activity.
* [Cortex XDR](https://www.paloaltonetworks.com/resources/datasheets/cortex-xdr) and [XSIAM](https://www.paloaltonetworks.com/resources/datasheets/cortex-xsiam-aag) block and alert on known techniques and files associated with Ignoble Scorpius. We provide XQL queries in the [MITRE ATT\&CK TTPs section](#post-137574-_pa5s1ucxb5t) of this report.
* Palo Alto Networks [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall) with [cloud-delivered security services](https://www.paloaltonetworks.com/network-security/security-subscriptions), including [Advanced WildFire](https://docs.paloaltonetworks.com/advanced-wildfire), detect known malicious files associated with Ignoble Scorpius.
* Organizations can engage the [Unit 42 Incident Response team](https://start.paloaltonetworks.com/contact-unit42.html) to help with a compromise or to provide a proactive assessment to lower your risk.

| **Related Unit 42 Topics** | [**BlackSuit Ransomware**](https://unit42.paloaltonetworks.com/tag/blacksuit-ransomware/), **[Royal Ransomware](https://unit42.paloaltonetworks.com/tag/royal-ransomware/), [Ignoble Scorpius](https://unit42.paloaltonetworks.com/tag/ignoble-scorpius/)** |
| **Related Unit 42 Themes** |                                                   [**Cybercrime**](https://unit42.paloaltonetworks.com/category/cybercrime/), **[Ransomware](https://unit42.paloaltonetworks.com/category/ransomware/)**                                                    |
|----------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|

## BlackSuit Ransomware Overview

BlackSuit ransomware emerged in May 2023 as a [rebrand of the Royal ransomware](https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-061a). Unit 42 Threat Intelligence assesses that the group behind this threat is a direct evolution of [Royal](https://unit42.paloaltonetworks.com/royal-ransomware/), and as such we track the group under the same moniker, Ignoble Scorpius.

Much like the operations as Royal ransomware, BlackSuit operates a dark web leak site where they publish their victims' names and stolen data to extort them into paying a ransom. Figure 1 shows an excerpt of this site.
![Screenshot of the BlackSuit ransomware leak site with much of the information redacted. The user has the ability to search the site. The text on the website talks about a company facing consequences after data was disclosed.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/11/image6.jpg) Figure 1. Screenshot of BlackSuit leak site.

Since the rebrand, Unit 42 has observed at least 93 victims globally and an upward trend in the number of successful compromises shared on their leak site. This suggests an overall ramping up of operations. Figure 2 below details the monthly total leak site posts from Ignoble Scorpius as BlackSuit.
![Bar chart of the number of leak site posts per month from May 2023 through October 2024. Activity peaks in May 2024.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/11/word-image-116463-137574-3.png) Figure 2. Activity from Ignoble Scorpius under the BlackSuit name, May 2023 through October 2024.

The number of organizations truly impacted by the group is likely higher, as organizations can pay their ransom before ransomware operators post details on their leak sites to avoid reputational damage.

The median revenue of these victims was $19.5 million, which highlights the average size of organizations that the group has successfully targeted. Based on ransom negotiations observed by Unit 42, we can also estimate that the group's initial ransom demand is equal to about 1.6% of the victim organization's annual revenue.

Breaking down the 93 victims by sector indicates a preference for the education, construction and manufacturing sectors, as shown in Figure 3 below.
![A pie chart showing the percentages by industry affected by Ignoble Scorpius. Education is the largest at 14%, then construction at 12.5%, manufacturing at 11%, and wholesale and retail at 10%.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/11/word-image-120193-137574-4.png) Figure 3. Pie chart breakdown of Ignoble Scorpius victimology.

Finally, as with many ransomware groups, Ignoble Scorpius' victims are overwhelmingly based in the United States, as shown below in Figure 4.
![A column chart of the distribution of Ignoble Scorpius's victim count by country. The highest count is the United States at close to 50. The next countries at counts under 10 are the United Kingdom, Belgium, German, Italy, Australia and others.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/11/word-image-123988-137574-5.png) Figure 4. Ignoble Scorpius' geographical impact.

## Attack Lifecycle

The following sections highlight tactics, techniques and procedures (TTPs) observed from Ignoble Scorpius during BlackSuit incident response investigations Unit 42 conducted. Similar findings have also been shared by researchers at [ReliaQuest](https://www.reliaquest.com/blog/blacksuit-attack-analysis/) and [The DFIR Report](https://thedfirreport.com/2024/08/26/blacksuit-ransomware/).

### Initial Access

Initial access for Ignoble Scorpius, and ransomware groups in general, can be highly varied due to the prevalence of initial access brokers (IABs) who sell stolen credentials or other forms of access to organizations. While some threat actors obtain initial access on their own, others require the expertise of IABs to gain entry into a compromised network.

During an incident response investigation, delineating between the TTPs of a suspected IAB or the ransomware group is not always possible. Within Ignoble Scorpius' ransomware cases, Unit 42 has observed many different initial access methods, including:

* Phishing campaigns with malicious email attachments ([T1566.001](https://attack.mitre.org/techniques/T1566/001/));
* SEO poisoning with [GootLoader](https://unit42.paloaltonetworks.com/javascript-malware-gootloader/) ([T1608.006](https://attack.mitre.org/techniques/T1608/006/));
* Using legitimate VPN credentials ([T1078](https://attack.mitre.org/techniques/T1078/)), potentially obtained via social engineering and voice-based phishing (aka vishing) of executives ([T1566.004](https://attack.mitre.org/techniques/T1566/004/))
* A software supply chain attack ([T1195.002](https://attack.mitre.org/techniques/T1195/002/)).

### Credential Access and Privilege Escalation

Unit 42 has observed Ignoble Scorpius using common credential theft tools, such as Mimikatz and [NanoDump](https://github.com/fortra/nanodump), which is "a flexible tool that creates a minidump of the LSASS process." Techniques observed include:

* Dumping LSASS via Taskmgr ([T1003.001](https://attack.mitre.org/techniques/T1003/001/))
* Performing a DCSync attack ([T1003.006](https://attack.mitre.org/techniques/T1003/006/))
* Using Impacket to conduct an adversary-in-the-middle (AiTM) attack ([T1557](https://attack.mitre.org/techniques/T1557/))
* Requesting Kerberos service tickets ([T1558.002](https://attack.mitre.org/techniques/T1558/002))

Once they have obtained sufficiently privileged accounts (i.e., domain administrator on Windows systems) Ignoble Scorpius has been observed dumping the NTDS.dit file via ntdsutil, ([T1003.003](https://attack.mitre.org/techniques/T1003/003)) to compromise the domain controller.

### Lateral Movement

Unit 42 has observed Ignoble Scorpius making use of RDP ([T1021.001](https://attack.mitre.org/techniques/T1021/001)), SMB ([T1021.002](https://attack.mitre.org/techniques/T1021/002)) and PsExec ([T1570](https://attack.mitre.org/techniques/T1570)) to move laterally across systems.

### Defense Evasion

Unit 42 has observed Ignoble Scorpius and other ransomware groups making use of a vulnerable driver and loader, which are called STONESTOP and POORTRY by [Mandiant](https://cloud.google.com/blog/topics/threat-intelligence/hunting-attestation-signed-malware/). They use these tools to disable and evade antivirus and EDR solutions ([T1562.001](https://attack.mitre.org/techniques/T1562/001)).

### Exfiltration

Ignoble Scorpius has used various commonly available software and services to exfiltrate victim data. We observed WinRAR and 7-Zip being used to compress and stage files prior to exfiltration, after which attackers used WinSCP over FTP and Rclone to exfiltrate files. In at least one instance, attackers renamed Rclone to svchost.exe prior to execution ([T1048](https://attack.mitre.org/techniques/T1048)).

Unit 42 has also observed Ignoble Scorpius using a third-party project management application named [Bublup](https://www.bublup.com/) to exfiltrate files ([T1567](https://attack.mitre.org/techniques/T1567), [T1567.002](https://attack.mitre.org/techniques/T1567/002)). Threat actors often abuse, take advantage of or subvert legitimate products for malicious purposes. This does not imply that the legitimate product is flawed or malicious.

### Execution and Impact

As Ignoble Scorpius' goal is to encrypt and ransom a victim's files, the primary payload of their campaigns is the BlackSuit ransomware. During incident response investigations involving BlackSuit, Unit 42 has also observed attackers using other tools for persistent access and the execution of arbitrary commands.

These additional tools include [Cobalt Strike](https://unit42.paloaltonetworks.com/tag/cobalt-strike/) and [SystemBC](https://www.kroll.com/en/insights/publications/cyber/inside-the-systembc-malware-server). In these cases it was not possible to identify whether Ignoble Scorpius or an IAB deployed the tools.

The final ransomware payload has Windows and Linux operating system variants with specific functionality to target VMware ESXi servers in some Linux variants.

#### Windows Variant

Unit 42's analysis of the Windows variant found that the execution of the malware required the command-line argument -id followed by a 32-character value. The ID identifies the victim and grants access to a private chat room on Ignoble Scorpius' dark website to negotiate the ransom. They provide the ID to the victim via the ransom note. An example ransom note is shown below:  
Good whatever time of day it is! Your safety service did a really poor job of protecting your files against our professionals. Extortioner named BlackSuit has attacked your system. As a result all your essential files were encrypted and saved at a secure server for further use and publishing on the Web into the public realm. Now we have all your files like: financial reports, intellectual property, accounting, law actions and complaints, personal files and so on and so forth. We are able to solve this problem in one touch. We (BlackSuit) are ready to give you an opportunity to get all the things back if you agree to make a deal with us. You have a chance to get rid of all possible financial, legal, insurance and many others risks and problems for a quite small compensation. You can have a safety review of your systems. All your files will be decrypted, your data will be reset, your systems will stay in safe. Contact us through TOR browser using the link: hxxp\[://\]weg7sdx54bevnvulapqu6bpzwztryeflq3s23tegbmnhkbpqz637f2yd\[.\]onion/?id=\[ID\]

|-------------------------------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 | Good whatever time of day it is! Your safety service did a really poor job of protecting your files against our professionals. Extortioner named BlackSuit has attacked your system. As a result all your essential files were encrypted and saved at a secure server for further use and publishing on the Web into the public realm. Now we have all your files like: financial reports, intellectual property, accounting, law actions and complaints, personal files and so on and so forth. We are able to solve this problem in one touch. We (BlackSuit) are ready to give you an opportunity to get all the things back if you agree to make a deal with us. You have a chance to get rid of all possible financial, legal, insurance and many others risks and problems for a quite small compensation. You can have a safety review of your systems. All your files will be decrypted, your data will be reset, your systems will stay in safe. Contact us through TOR browser using the link: hxxp\[://\]weg7sdx54bevnvulapqu6bpzwztryeflq3s23tegbmnhkbpqz637f2yd\[.\]onion/?id=\[ID\] |

Other command-line arguments for the Windows variant of BlackSuit malware are shown below in Table 1.

|--------------|-----------------------------------------------|
| **Argument** | **Functionality**                             |
| -path        | Specifies a target directory to encrypt       |
| -id          | Victim ID                                     |
| -ep          | Percentage of a file that should be encrypted |
| -localonly   | Encrypts only the local system                |
| -networkonly | Encrypts file shares connected to the system  |

Table 1. BlackSuit Windows variant command-line arguments.

Analysis of BlackSuit ransomware from [TrendMicro](https://www.trendmicro.com/en_us/research/23/e/investigating-blacksuit-ransomwares-similarities-to-royal.html) and [SentinelOne](https://www.sentinelone.com/anthology/blacksuit/) in 2023 identified more command-line flags than recent samples. This could be due to the ransomware group creating variants that target ESXi servers specifically, [which we detail below](#post-137574-_39nw4kl81362), or a consolidation of functionality.

After the initial execution, the malware creates a mutual exclusion flag (aka mutex) with the value Global\\WLm87eV1oNRx6P3E4Cy9 to prevent machines from being infected multiple times. As a result, the mutex chosen by Ignoble Scorpius needs to be a unique value that is not frequently changed. Unit 42 has observed attackers using this mutex as recently as June 2024, with open source highlighting its use as early as [October 2023](https://www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/ransom.win32.blacksuit.ypdjb).

To ensure the encryption of as many files as possible, the ransomware enumerates and terminates a list of known processes and services ([T1057](https://attack.mitre.org/techniques/T1057)). The ransomware also uses Windows Restart Manager (rstrtmgr.dll) to identify processes using files that would prevent encryption, terminating anything that isn't a critical process or the Windows File Explorer (explorer.exe). This is a technique [commonly used by ransomware payloads](https://www.crowdstrike.com/blog/windows-restart-manager-part-1/).

The malware uses the following command to delete shadow backups ([T1490](https://attack.mitre.org/techniques/T1490)):

![Screenshot of code snippet that deletes versions.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/11/word-image-127276-137574-6.png)

To execute the ransomware payload, researchers at [ReliaQuest](https://www.reliaquest.com/blog/blacksuit-attack-analysis/) observed Ignoble Scorpius downloading VirtualBox and creating a virtual machine (VM) ([T1564.006](https://attack.mitre.org/techniques/T1564/006)). They copied the ransomware payload from the VM using PsExec ([T1570](https://attack.mitre.org/techniques/T1570)) to "hundreds of hosts via SMB" ([T1021.002](https://attack.mitre.org/techniques/T1021/002)). They then used Windows Management Instrumentation Command-line (WMIC) to load the ransomware as a library to execute it. This is a technique that Unit 42 has also observed from the group ([T1047](https://attack.mitre.org/techniques/T1047), [T1218.010](https://attack.mitre.org/techniques/T1218/010)).

They then enumerate available files ([T1083](https://attack.mitre.org/techniques/T1083/)) and encrypt them using OpenSSL AES, adding the extension .blacksuit to the encrypted file's name ([T1486](https://attack.mitre.org/techniques/T1486)).

#### ESXi Variant

The ESXi variant, a Linux-based executable, targets virtual machines and introduces two more command-line flags:

* \-vmkill (shuts down virtual machines before encryption if set)
* \-crypt\_all

If the -crypt\_all flag is not set, the following files relating to VMware are encrypted:

* \*.vmsd
* \*.vmx
* \*.vmxf
* \*.vmdk
* \*.vmem
* \*.vmsn
* \*.nvram
* \*.vmx~
* \*.vswp
* \*.vmtx
* \*.vmss

## Conclusion

Our analysis indicates that BlackSuit is a direct continuation of the activity under Royal, and as such we have opted to continue tracking the group under the same identifier as Royal -- Ignoble Scorpius. The true effectiveness of rebranding is difficult to quantify. However, it can offer ransomware groups a respite from the scrutiny of researchers, law enforcement and the media.

A more subtle effect of rebranding is the perception it can have on defenders. For example, BlackSuit's predecessor Royal and their predecessor Conti were some of the most reported and sophisticated ransomware groups while active.

As a result, organizations who were looking to assess their exposure to ransomware at the time could have looked toward the most prolific ransomware groups and attempted to cater their defensive solutions toward them. Rebranding resets this perception, and if it is accompanied with a shift in the group's TTPs, it can place defenders on their back foot.

This is one of the primary reasons we chose to highlight Ignoble Scorpius' BlackSuit ransomware in this report. Although the group as BlackSuit might not yet reach the top 10 list of ransomware groups by number of compromises, this group has the following qualities:

* They conduct complex supply chain attacks
* They exhibit a high level of sophistication compromising at least 93 organizations without a public-facing RaaS program
* Their membership likely includes members from Conti and Royal ransomware

This report maps the group's activity to the MITRE ATT\&CK framework in the [that section](#post-137574-_pa5s1ucxb5t) below. Organizations can use this information to assess their coverage of threats posed by Ignoble Scorpius, pre- and post-compromise.

## Protections and Mitigations

Palo Alto Networks customers are better protected from the threats discussed above through the following products:

* The Unit 42 [Managed Threat Hunting](https://www.paloaltonetworks.com/unit42/respond/managed-threat-hunting) and [Managed Detection and Response](https://www.paloaltonetworks.com/resources/datasheets/unit42-managed-detection-and-response) teams conduct proactive hunts for pre- and post-incident activity.
* [Cortex XDR](https://www.paloaltonetworks.com/resources/datasheets/cortex-xdr) and [XSIAM](https://www.paloaltonetworks.com/resources/datasheets/cortex-xsiam-aag) block and alert on known techniques and files associated with Ignoble Scorpius. We provide XQL queries in the [MITRE ATT\&CK TTPs section](#post-137574-_pa5s1ucxb5t) of this report.
* Palo Alto Networks [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall) with [Cloud-Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions), including [Advanced WildFire](https://docs.paloaltonetworks.com/advanced-wildfire), detect known malicious files associated with Ignoble Scorpius.

If you think you may have been compromised or have an urgent matter, get in touch with the[Unit 42 Incident Response team](https://start.paloaltonetworks.com/contact-unit42.html) or call:

* North America Toll-Free: 866.486.4842 (866.4.UNIT42)
* EMEA: +31.20.299.3130
* APAC: +65.6983.8730
* Japan: +81.50.1790.0200

Palo Alto Networks has shared these findings with our fellow Cyber Threat Alliance (CTA) members. CTA members use this intelligence to rapidly deploy protections to their customers and to systematically disrupt malicious cyber actors. Learn more about the [Cyber Threat Alliance](https://www.cyberthreatalliance.org).

## Additional Resources

* [BlackSuit Attack Analysis](https://www.reliaquest.com/blog/blacksuit-attack-analysis/) -- ReliaQuest Threat Research Team
* [BlackSuit Ransomware](https://thedfirreport.com/2024/08/26/blacksuit-ransomware/) -- The DFIR Report
* [Threat Actor Spotlight: BlackSuit Ransomware](https://areteir.com/article/understanding-blacksuit-ransomware/) -- Arete Incident Response
* [#StopRansomware: Blacksuit (Royal) Ransomware](https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-061a) -- Cybersecurity and Infrastructure Security Agency (CISA)

## MITRE ATT\&CK TTPs

Table 2 below depicts the MITRE ATT\&CK TTPs mapping for techniques referenced in this report.

|-----------|--------------------------------------------------------------------|---------------------------------------------------------------------------------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **ID**    | **Tactic**                                                         | **Technique Name**                                                                                            | **Procedure**                                                                                                                                                          |
| T1570     | Lateral Movement                                                   | [Lateral Tool Transfer](https://attack.mitre.org/techniques/T1570/)                                           | Uses PsExec for lateral movement and tool transfer                                                                                                                     |
| T1567.002 | Exfiltration                                                       | [Exfiltration Over Web Service: Exfiltration to Cloud Storage](https://attack.mitre.org/techniques/T1567/002) | Uses RClone and Bublup for data exfiltration                                                                                                                           |
| T1566.004 | Initial Access                                                     | [Phishing: Spearphishing Voice](https://attack.mitre.org/techniques/T1566/004/)                               | Uses vishing with executives                                                                                                                                           |
| T1566.001 | Initial Access                                                     | [Phishing: Spearphishing Attachment](https://attack.mitre.org/techniques/T1566/001/)                          | Sends phishing emails using malicious attachments                                                                                                                      |
| T1564.006 | Defense Evasion                                                    | [Hide Artifacts: Run Virtual Instance](https://attack.mitre.org/techniques/T1564/006/)                        | Uses VirtualBox to create virtual machines                                                                                                                             |
| T1562.001 | Defense Evasion                                                    | [Impair Defenses: Disable or Modify Tools](https://attack.mitre.org/techniques/T1562/001/)                    | Vulnerable drivers/loaders used to disable and evade antivirus and EDR solutions                                                                                       |
| T1558.004 | Credential Access                                                  | [Steal or Forge Kerberos Tickets: AS-REP Roasting](https://attack.mitre.org/techniques/T1558/004/)            | Uses toolkits such as Rubeus to compromise accounts using AS-REP roasting                                                                                              |
| T1558.003 | Credential Access                                                  | [Steal or Forge Kerberos Tickets: Kerberoasting](https://attack.mitre.org/techniques/T1558/003/)              | Uses toolkits such as Rubeus to compromise accounts using Kerberoasting                                                                                                |
| T1558.002 | Credential Access                                                  | [Steal or Forge Kerberos Tickets: Silver Ticket](https://attack.mitre.org/techniques/T1558/002/)              | Requests Kerberos service tickets                                                                                                                                      |
| T1557     | Collection, Credential Access                                      | [Adversary-in-the-Middle](https://attack.mitre.org/techniques/T1557/)                                         | Uses Impacket to conduct AitM attacks                                                                                                                                  |
| T1490     | Impact                                                             | [Inhibit System Recovery](https://attack.mitre.org/techniques/T1490/)                                         | Deletes shadow copies using a specific vssadmin.exe command                                                                                                            |
| T1486     | Impact                                                             | [Data Encrypted for Impact](https://attack.mitre.org/techniques/T1486/)                                       | Files are encrypted with the .blacksuit file extension                                                                                                                 |
| T1218.010 | Defense Evasion                                                    | [System Binary Proxy Execution: Regsvr32](https://attack.mitre.org/techniques/T1218/010/)                     | WMIC used to load the ransomware as a library, executing it through regsvr32.exe                                                                                       |
| T1195.002 | Initial Access                                                     | [Supply Chain Compromise: Compromise Software Supply Chain](https://attack.mitre.org/techniques/T1195/002/)   | Uses supply chain compromise for initial access                                                                                                                        |
| T1189     | Initial Access                                                     | [Drive-by Compromise](https://attack.mitre.org/techniques/T1189/)                                             | Search engine optimization (SEO) poisoning with GootLoader                                                                                                             |
| T1140     | Defense Evasion                                                    | [Deobfuscate/Decode Files or Information](https://attack.mitre.org/techniques/T1140/)                         | Uses stack strings to obfuscate data                                                                                                                                   |
| T1110     | Credential Access                                                  | [Brute Force](https://attack.mitre.org/techniques/T1110/)                                                     | Conducted brute-force attacks against virtual private network (VPN) gateways not configured with multi-factor authentication (MFA)                                     |
| T1083     | Discovery                                                          | [File and Directory Discovery](https://attack.mitre.org/techniques/T1083/)                                    | Enumerates files and encrypts all found                                                                                                                                |
| T1078     | Defense Evasion, Initial Access, Persistence, Privilege Escalation | [Valid Accounts](https://attack.mitre.org/techniques/T1078/)                                                  | Uses legitimate VPN credentials or password dumps                                                                                                                      |
| T1071     | Command and Control                                                | [Application Layer Protocol](https://attack.mitre.org/techniques/T1071/)                                      | Uses multiple protocols alongside the Cobalt Strike post-exploitation framework                                                                                        |
| T1059.007 | Execution                                                          | [Command and Scripting Interpreter: JavaScript](https://attack.mitre.org/techniques/T1059/007)                | Wscript makes an external connection upon executing a JavaScript file                                                                                                  |
| T1059.001 | Execution                                                          | [Command and Scripting Interpreter: PowerShell](https://attack.mitre.org/techniques/T1059/001)                | Uses the default PowerShell string for command execution on a remote host                                                                                              |
| T1057     | Discovery                                                          | [Process Discovery](https://attack.mitre.org/techniques/T1057/)                                               | The Windows Restart Manager (rstrtmgr.dll) is used to identify processes using files that would prevent encryption, terminating anything that isn't a critical process |
| T1048     | Exfiltration                                                       | [Exfiltration Over Alternative Protocol](https://attack.mitre.org/techniques/T1048/)                          | Rclone is sometimes renamed to svchost.exe prior to execution and exfiltration over alternative protocols                                                              |
| T1047     | Execution                                                          | [Windows Management Instrumentation](https://attack.mitre.org/techniques/T1047/)                              | Impacket framework execution relating to wmiexec; uses WMIC to load the ransomware as a library                                                                        |
| T1036     | Defense Evasion                                                    | [Masquerading](https://attack.mitre.org/techniques/T1036/)                                                    | Renaming PE files (e.g., Rclone.exe to 1.exe)                                                                                                                          |
| T1027.007 | Defense Evasion                                                    | [Obfuscated Files or Information: Dynamic API Resolution](https://attack.mitre.org/techniques/T1027/007/)     | Uses dynamic API resolution to conceal functionality                                                                                                                   |
| T1021.002 | Lateral Movement                                                   | [Remote Services: SMB/Windows Admin Shares](https://attack.mitre.org/techniques/T1021/002/)                   | Copies the ransomware payload from VMs using PSExec to numerous hosts using SMB                                                                                        |
| T1021.001 | Lateral Movement                                                   | [Remote Services: Remote Desktop Protocol](https://attack.mitre.org/techniques/T1021/001/)                    | Uses remote desktop protocol (RDP) for lateral movement                                                                                                                |
| T1003.006 | Credential Access                                                  | [OS Credential Dumping: DCSync](https://attack.mitre.org/techniques/T1003/006/)                               | Conducts a DCSync attack for credential access                                                                                                                         |
| T1003.003 | Credential Access                                                  | [OS Credential Dumping: NTDS](https://attack.mitre.org/techniques/T1003/003/)                                 | Uses ntdsutil.exe to dump Active Directory database                                                                                                                    |
| T1003.001 | Credential Access                                                  | [OS Credential Dumping: LSASS Memory](https://attack.mitre.org/techniques/T1003/001/)                         | LSASS dumped via the Task Manager                                                                                                                                      |

Table 2. MITRE ATT\&CK techniques.

## XDR Query Language (XQL) Queries

This section documents relevant TTPs used by Ignoble Scorpius and maps them directly to Palo Alto Networks Cortex XQL queries. These queries detect renamed tools with Cortex XDR.

Like many ransomware actors, Ignoble Scorpius likes to rename their Portable Executable (PEs) files. For example, rather than execute a tool such as Rclone as rclone.exe, the actor might rename it to something else, such as svchost.exe.

In the case mentioned above, a query for action\_process\_image\_name = "rclone.exe" in Cortex XDR's Query Language (XQL) will fail. However, Cortex XDR can identify these files even if they've been renamed.

When a PE is compiled, it often includes a resource called [VERSIONINFO](https://learn.microsoft.com/en-us/windows/win32/menurc/versioninfo-resource). This resource can contain the original file name, the company that produced the software, and more. Though ransomware actors can rename executables, they rarely alter the VERSIONINFO resource.

We can extract the VERSIONINFO from PEs that run on a host using Cortex XDR with the action\_process\_file\_info field in the ENUM.PROCESS filter set, shown in the following XQL query snippet.  
config case\_sensitive = false | dataset = xdr\_data | filter event\_type = ENUM.PROCESS and event\_sub\_type = ENUM.PROCESS\_START | alter action\_process\_original\_name = action\_process\_file\_info -\> original\_name, action\_process\_company\_name = action\_process\_file\_info -\> company, action\_process\_description = action\_process\_file\_info -\> description, action\_process\_internal\_name = action\_process\_file\_info -\> internal\_name, action\_process\_legal\_copyright = action\_process\_file\_info -\> legal\_copyright

|-------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 | config case\_sensitive = false | dataset = xdr\_data | filter event\_type = ENUM.PROCESS and event\_sub\_type = ENUM.PROCESS\_START | alter action\_process\_original\_name = action\_process\_file\_info -\> original\_name, action\_process\_company\_name = action\_process\_file\_info -\> company, action\_process\_description = action\_process\_file\_info -\> description, action\_process\_internal\_name = action\_process\_file\_info -\> internal\_name, action\_process\_legal\_copyright = action\_process\_file\_info -\> legal\_copyright |

Table 3 below highlights data from the VERSIONINFO resource, which is extracted for running processes by the above query.

|----------------------|-------------------------------------------------------------------------------------------|
| **VERSIONINFO Data** | **Description**                                                                           |
| original\_name        | The original name of a PE upon compilation                                                |
| company              | The company that released the software                                                    |
| description          | A description of the compiled software                                                    |
| internal\_name        | The internal name of the PE. This is often equal to or very similar to the original\_name. |
| legal\_copyright      | A copyright notification from the releasing company                                       |

Table 3. Ignoble Scorpius data extraction.

Once the VERSIONINFO data has been extracted, XQL can then be used to filter on known version info values from executables. The following is an example filter set that will identify renamed versions of Rclone's default executable, rclone.exe.  
| filter (action\_process\_image\_name = "rclone.exe" or action\_process\_original\_name ~= "rclone" or action\_process\_company\_name ~= "https\\:\\/\\/rclone\\.org" or action\_process\_description ~= "rclone" or action\_process\_internal\_name ~= "rclone" or action\_process\_legal\_copyright = "The Rclone Authors")

|-------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 | | filter (action\_process\_image\_name = "rclone.exe" or action\_process\_original\_name ~= "rclone" or action\_process\_company\_name ~= "https\\:\\/\\/rclone\\.org" or action\_process\_description ~= "rclone" or action\_process\_internal\_name ~= "rclone" or action\_process\_legal\_copyright = "The Rclone Authors") |

Some of the Cortex XDR queries we've included in this report use the above method for identifying renamed executables.

### 1. GootLoader: Wscript Making External Connection

**Technique description:** The query looks for wscript.exe making external connections upon executing a JavaScript (.js) file, which could be indicative of GootLoader activity. The query restricts results to user-based Downloads or Temp folders, as these are the directories most commonly associated with GootLoader infections.

#### MITRE ATT\&CK TTP ID

* T1059.007 Execution - Command and Scripting Interpreter: JavaScript

#### XQL Query

config case\_sensitive = false timeframe = 30d | dataset = xdr\_data | filter event\_type = ENUM.STORY and agent\_os\_type = ENUM.AGENT\_OS\_WINDOWS | filter actor\_process\_image\_name = "wscript.exe" and actor\_process\_command\_line contains ".js" | filter actor\_process\_command\_line contains "\\Users\\\*\\Downloads" or actor\_process\_command\_line contains "\\Users\\\*\\Temp" | filter dst\_is\_internal\_ip = False | fields \_time, agent\_hostname, actor\_effective\_username,actor\_process\_image\_name, actor\_process\_command\_line, action\_remote\_ip, dst\_action\_external\_hostname | sort desc \_time

|-------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 | config case\_sensitive = false timeframe = 30d | dataset = xdr\_data | filter event\_type = ENUM.STORY and agent\_os\_type = ENUM.AGENT\_OS\_WINDOWS | filter actor\_process\_image\_name = "wscript.exe" and actor\_process\_command\_line contains ".js" | filter actor\_process\_command\_line contains "\\Users\\\*\\Downloads" or actor\_process\_command\_line contains "\\Users\\\*\\Temp" | filter dst\_is\_internal\_ip = False | fields \_time, agent\_hostname, actor\_effective\_username,actor\_process\_image\_name, actor\_process\_command\_line, action\_remote\_ip, dst\_action\_external\_hostname | sort desc \_time |

### 2. Dumping LSASS via Task Manager

**Technique description:** The query looks for LSASS being dumped via the Task Manager. To identify this activity, we focus on lsass.DMP files being created via the Taskmgr.exe process.

#### MITRE ATT\&CK TTP ID

* T1003.001 Credential Access - OS Credential Dumping: LSASS Memory

#### XQL Query

config case\_sensitive = false timeframe = 30d | dataset = xdr\_data | filter event\_type = ENUM.FILE and event\_sub\_type = ENUM.FILE\_CREATE\_NEW and agent\_os\_type = ENUM.AGENT\_OS\_WINDOWS | filter action\_file\_name = "lsass.DMP" and actor\_process\_image\_name = "Taskmgr.exe" | fields agent\_hostname, event\_type, event\_sub\_type, action\_file\_name, action\_file\_path, action\_file\_sha256, action\_file\_md5, actor\_process\_image\_name, actor\_process\_image\_path, actor\_process\_image\_command\_line | sort desc \_time

|-------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 | config case\_sensitive = false timeframe = 30d | dataset = xdr\_data | filter event\_type = ENUM.FILE and event\_sub\_type = ENUM.FILE\_CREATE\_NEW and agent\_os\_type = ENUM.AGENT\_OS\_WINDOWS | filter action\_file\_name = "lsass.DMP" and actor\_process\_image\_name = "Taskmgr.exe" | fields agent\_hostname, event\_type, event\_sub\_type, action\_file\_name, action\_file\_path, action\_file\_sha256, action\_file\_md5, actor\_process\_image\_name, actor\_process\_image\_path, actor\_process\_image\_command\_line | sort desc \_time |

### 3. Impacket Process Execution

**Technique description:** The query looks for signs of Impacket framework execution, especially relating to smbexec and wmiexec. It focuses on the default PowerShell string used for command execution on the remote host.

#### MITRE ATT\&CK TTP IDs

* T1059.001 Execution - Command and Scripting Interpreter: PowerShell
* T1047 Execution - Windows Management Instrumentation

#### XQL Query

config case\_sensitive = false timeframe = 30d | dataset = xdr\_data | filter event\_type = ENUM.PROCESS and agent\_os\_type = ENUM.AGENT\_OS\_WINDOWS | filter (causality\_actor\_process\_image\_name = "wmiprvse.exe" or causality\_actor\_process\_image\_name = "services.exe") and actor\_process\_image\_name = "powershell.exe" | filter actor\_process\_command\_line ~= "-NoP -NoL -sta -NonI -W Hidden -Exec Bypass -Enc" | sort desc \_time

|-------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 | config case\_sensitive = false timeframe = 30d | dataset = xdr\_data | filter event\_type = ENUM.PROCESS and agent\_os\_type = ENUM.AGENT\_OS\_WINDOWS | filter (causality\_actor\_process\_image\_name = "wmiprvse.exe" or causality\_actor\_process\_image\_name = "services.exe") and actor\_process\_image\_name = "powershell.exe" | filter actor\_process\_command\_line ~= "-NoP -NoL -sta -NonI -W Hidden -Exec Bypass -Enc" | sort desc \_time |

### 4. Mimikatz and Rubeus Execution

**Technique description:** The query looks for signs of Mimiktaz or Rubeus executing within the environment. It takes into account renamed process image files by using PE metadata to identify VERSIONINFO data of executing processes.

#### MITRE ATT\&CK TTP ID

* T1003.001 Credential Access - OS Credential Dumping: LSASS Memory

#### XQL Query

config case\_sensitive = false timeframe = 30d | dataset = xdr\_data | filter event\_type = ENUM.PROCESS and event\_sub\_type = ENUM.PROCESS\_START and agent\_os\_type = ENUM.AGENT\_OS\_WINDOWS | alter action\_process\_original\_name = action\_process\_file\_info -\> original\_name, action\_process\_company\_name = action\_process\_file\_info -\> company, action\_process\_description = action\_process\_file\_info -\> description, action\_process\_internal\_name = action\_process\_file\_info -\> internal\_name, action\_process\_legal\_copyright = action\_process\_file\_info -\> legal\_copyright | filter (action\_process\_image\_name ~= "(mimikatz|rubeus)\\.exe" or action\_process\_original\_name ~= "(mimikatz|rubeus)" or action\_process\_description ~= "(mimikatz|rubeus)" or action\_process\_internal\_name ~= "(mimikatz|rubeus)") | fields \_time, agent\_hostname, agent\_ip\_addresses, actor\_effective\_username, action\_process\_image\_name, action\_process\_image\_path, action\_process\_image\_command\_line, action\_process\_image\_sha256, actor\_process\_image\_name, actor\_process\_image\_path, actor\_process\_command\_line, actor\_process\_image\_sha256, os\_actor\_process\_command\_line, action\_process\_original\_name, action\_process\_company\_name, action\_process\_description, action\_process\_internal\_name, action\_process\_legal\_copyright, action\_process\_file\_info | sort desc \_time

|-------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 | config case\_sensitive = false timeframe = 30d | dataset = xdr\_data | filter event\_type = ENUM.PROCESS and event\_sub\_type = ENUM.PROCESS\_START and agent\_os\_type = ENUM.AGENT\_OS\_WINDOWS | alter action\_process\_original\_name = action\_process\_file\_info -\> original\_name, action\_process\_company\_name = action\_process\_file\_info -\> company, action\_process\_description = action\_process\_file\_info -\> description, action\_process\_internal\_name = action\_process\_file\_info -\> internal\_name, action\_process\_legal\_copyright = action\_process\_file\_info -\> legal\_copyright | filter (action\_process\_image\_name ~= "(mimikatz|rubeus)\\.exe" or action\_process\_original\_name ~= "(mimikatz|rubeus)" or action\_process\_description ~= "(mimikatz|rubeus)" or action\_process\_internal\_name ~= "(mimikatz|rubeus)") | fields \_time, agent\_hostname, agent\_ip\_addresses, actor\_effective\_username, action\_process\_image\_name, action\_process\_image\_path, action\_process\_image\_command\_line, action\_process\_image\_sha256, actor\_process\_image\_name, actor\_process\_image\_path, actor\_process\_command\_line, actor\_process\_image\_sha256, os\_actor\_process\_command\_line, action\_process\_original\_name, action\_process\_company\_name, action\_process\_description, action\_process\_internal\_name, action\_process\_legal\_copyright, action\_process\_file\_info | sort desc \_time |

### 5. Active Directory Dumping via NTDSUTIL

**Technique description:** The query looks for the use of ntdsutil.exe to dump the Active Directory database (NTDS.dit).

#### MITRE ATT\&CK TTP ID

* Credential Access - T1003.003 OS Credential Dumping: NTDS

#### XQL Query

config case\_sensitive = false timeframe = 30d | dataset = xdr\_data | filter event\_type = ENUM.PROCESS and event\_sub\_type = ENUM.PROCESS\_START and agent\_os\_type = ENUM.AGENT\_OS\_WINDOWS | filter action\_process\_image\_name = "ntdsutil.exe" and (action\_process\_image\_command\_line contains "ac i ntds" or action\_process\_image\_command\_line contains "activate instance ntds") and action\_process\_image\_command\_line contains "create full" | fields \_time, agent\_hostname, agent\_ip\_addresses, actor\_effective\_username, action\_process\_image\_name, action\_process\_image\_path, action\_process\_image\_command\_line, action\_process\_image\_sha256, actor\_process\_image\_name, actor\_process\_image\_path, actor\_process\_command\_line, actor\_process\_image\_sha256, os\_actor\_process\_command\_line, action\_process\_file\_info | sort desc \_time

|-------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 | config case\_sensitive = false timeframe = 30d | dataset = xdr\_data | filter event\_type = ENUM.PROCESS and event\_sub\_type = ENUM.PROCESS\_START and agent\_os\_type = ENUM.AGENT\_OS\_WINDOWS | filter action\_process\_image\_name = "ntdsutil.exe" and (action\_process\_image\_command\_line contains "ac i ntds" or action\_process\_image\_command\_line contains "activate instance ntds") and action\_process\_image\_command\_line contains "create full" | fields \_time, agent\_hostname, agent\_ip\_addresses, actor\_effective\_username, action\_process\_image\_name, action\_process\_image\_path, action\_process\_image\_command\_line, action\_process\_image\_sha256, actor\_process\_image\_name, actor\_process\_image\_path, actor\_process\_command\_line, actor\_process\_image\_sha256, os\_actor\_process\_command\_line, action\_process\_file\_info | sort desc \_time |

### 6. Cobalt Strike Combined Query

**Technique description:** The query looks for a combination of identifiers related to the Cobalt Strike post-exploitation framework. Though the tool is used legitimately by pentesting, red teaming and emulation teams alike, threat actors such as BlackSuit also like to use the tool.

#### MITRE ATT\&CK TTP ID

* T1071 Command and Control - Application Layer Protocol

#### XQL Query

config case\_sensitive = false timeframe = 30d | dataset = xdr\_data | filter (event\_type = ENUM.PROCESS AND event\_sub\_type = ENUM.PROCESS\_START and actor\_process\_image\_name = "services.exe" and action\_process\_image\_command\_line ~= ".+\\\\admin\\$\\\\\[a-z0-9\]{7}\\.exe") or (event\_type = ENUM.PROCESS AND event\_sub\_type = ENUM.PROCESS\_START and (action\_process\_image\_command\_line = "c:\\windows\\system32\\rundll32.exe" or action\_process\_image\_command\_line = "c:\\windows\\syswow64\\rundll32.exe" and actor\_process\_image\_name != "setup.exe" and actor\_process\_command\_line not contains "chrome" and actor\_process\_command\_line not contains "edge")) or (event\_type = ENUM.FILE and action\_file\_path ~= "\\\\device\\\\namedpipe\\\\msse-\\d+-server" or action\_file\_path ~= "\\\\device\\\\namedpipe\\\\postex\_\[a-z0-9\]{4}" or action\_file\_path ~= "\\\\device\\\\namedpipe\\\\status\_\[a-z0-9\]{4}" or action\_file\_path ~= "\\\\device\\\\namedpipe\\\\msagent\_\[a-z0-9\]{4}") or (event\_type = ENUM.PROCESS AND event\_sub\_type = ENUM.PROCESS\_START and (action\_process\_image\_name contains "powershell.exe" OR actor\_process\_image\_name contains "cmd.exe") AND ((action\_process\_image\_command\_line contains "-enc jabzad0" OR action\_process\_image\_command\_line contains "-encodedcommand jabzad0"))) or (event\_type = ENUM.STORY and dst\_action\_external\_hostname contains "aaa.stage") or (event\_type = ENUM.EVENT\_LOG and (action\_evtlog\_message ~= "\\$s=New-Object IO.MemoryStream" OR action\_evtlog\_message ~= "\\$var\_code")) | fields agent\_hostname, agent\_id, agent\_ip\_addresses , agent\_version, actor\_effective\_username, actor\_process\_image\_name, actor\_process\_image\_path, actor\_process\_command\_line, action\_process\_image\_command\_line, action\_file\_path, action\_evtlog\_username, action\_evtlog\_message, actor\_process\_signature\_vendor | filter not ((actor\_process\_image\_path contains "Microsoft\\EdgeWebView\\Application" or actor\_process\_image\_path contains "Microsoft\\EdgeUpdate\\Install" or actor\_process\_image\_path contains "Microsoft\\Edge\\Application" or actor\_process\_image\_path contains "Chromium" or actor\_process\_image\_path contains "Installer\\setup.exe") and (actor\_process\_signature\_vendor = "Microsoft Corporation" or actor\_process\_image\_name = "setup.exe")) | sort desc \_time

|-------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 | config case\_sensitive = false timeframe = 30d | dataset = xdr\_data | filter (event\_type = ENUM.PROCESS AND event\_sub\_type = ENUM.PROCESS\_START and actor\_process\_image\_name = "services.exe" and action\_process\_image\_command\_line ~= ".+\\\\admin\\$\\\\\[a-z0-9\]{7}\\.exe") or (event\_type = ENUM.PROCESS AND event\_sub\_type = ENUM.PROCESS\_START and (action\_process\_image\_command\_line = "c:\\windows\\system32\\rundll32.exe" or action\_process\_image\_command\_line = "c:\\windows\\syswow64\\rundll32.exe" and actor\_process\_image\_name != "setup.exe" and actor\_process\_command\_line not contains "chrome" and actor\_process\_command\_line not contains "edge")) or (event\_type = ENUM.FILE and action\_file\_path ~= "\\\\device\\\\namedpipe\\\\msse-\\d+-server" or action\_file\_path ~= "\\\\device\\\\namedpipe\\\\postex\_\[a-z0-9\]{4}" or action\_file\_path ~= "\\\\device\\\\namedpipe\\\\status\_\[a-z0-9\]{4}" or action\_file\_path ~= "\\\\device\\\\namedpipe\\\\msagent\_\[a-z0-9\]{4}") or (event\_type = ENUM.PROCESS AND event\_sub\_type = ENUM.PROCESS\_START and (action\_process\_image\_name contains "powershell.exe" OR actor\_process\_image\_name contains "cmd.exe") AND ((action\_process\_image\_command\_line contains "-enc jabzad0" OR action\_process\_image\_command\_line contains "-encodedcommand jabzad0"))) or (event\_type = ENUM.STORY and dst\_action\_external\_hostname contains "aaa.stage") or (event\_type = ENUM.EVENT\_LOG and (action\_evtlog\_message ~= "\\$s=New-Object IO.MemoryStream" OR action\_evtlog\_message ~= "\\$var\_code")) | fields agent\_hostname, agent\_id, agent\_ip\_addresses , agent\_version, actor\_effective\_username, actor\_process\_image\_name, actor\_process\_image\_path, actor\_process\_command\_line, action\_process\_image\_command\_line, action\_file\_path, action\_evtlog\_username, action\_evtlog\_message, actor\_process\_signature\_vendor | filter not ((actor\_process\_image\_path contains "Microsoft\\EdgeWebView\\Application" or actor\_process\_image\_path contains "Microsoft\\EdgeUpdate\\Install" or actor\_process\_image\_path contains "Microsoft\\Edge\\Application" or actor\_process\_image\_path contains "Chromium" or actor\_process\_image\_path contains "Installer\\setup.exe") and (actor\_process\_signature\_vendor = "Microsoft Corporation" or actor\_process\_image\_name = "setup.exe")) | sort desc \_time |

### 7. Rclone Exfiltration

**Technique description:** The query looks for data exfiltration via Rclone, a tool used by BlackSuit to exfiltrate data from victim environments. It takes into account renamed process image files by using PE metadata to identify VERSIONINFO data of executing processes.

#### MITRE ATT\&CK TTP IDs

* T1567 Exfiltration - Exfiltration Over Web Service

#### XQL Query

config case\_sensitive = false timeframe = 30d | dataset = xdr\_data | filter event\_type = ENUM.PROCESS and event\_sub\_type = ENUM.PROCESS\_START and agent\_os\_type = ENUM.AGENT\_OS\_WINDOWS | alter action\_process\_original\_name = action\_process\_file\_info -\> original\_name, action\_process\_company\_name = action\_process\_file\_info -\> company, action\_process\_description = action\_process\_file\_info -\> description, action\_process\_internal\_name = action\_process\_file\_info -\> internal\_name, action\_process\_legal\_copyright = action\_process\_file\_info -\> legal\_copyright | filter (action\_process\_image\_name = "rclone.exe" or action\_process\_original\_name ~= "rclone" or action\_process\_company\_name ~= "https\\:\\/\\/rclone\\.org" or action\_process\_description ~= "rclone" or action\_process\_internal\_name ~= "rclone" or action\_process\_legal\_copyright = "The Rclone Authors") and action\_process\_image\_command\_line in ("\*lsd\*", "\*remote:\*", "\*mega\*", "\*--config\*", "\*--auto-confirm\*", "\*or --multi-thread-streams and copy\*", "\*config\*", "\*create\*", "\*user\*", "\*pass\*", "\*progress\*", "\*no-check-certificate\*", "\*ignore-existing\*", "\*auto-confirm\*", "\*multi-thread-streams\*", "\*transfers\*", "\*ftp:\*") | fields \_time, agent\_hostname, agent\_ip\_addresses, actor\_effective\_username, action\_process\_image\_name, action\_process\_image\_path, action\_process\_image\_command\_line, action\_process\_image\_sha256, actor\_process\_image\_name, actor\_process\_image\_path, actor\_process\_command\_line, actor\_process\_image\_sha256, os\_actor\_process\_command\_line | sort desc \_time

|-------------------------------------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 | config case\_sensitive = false timeframe = 30d | dataset = xdr\_data | filter event\_type = ENUM.PROCESS and event\_sub\_type = ENUM.PROCESS\_START and agent\_os\_type = ENUM.AGENT\_OS\_WINDOWS | alter action\_process\_original\_name = action\_process\_file\_info -\> original\_name, action\_process\_company\_name = action\_process\_file\_info -\> company, action\_process\_description = action\_process\_file\_info -\> description, action\_process\_internal\_name = action\_process\_file\_info -\> internal\_name, action\_process\_legal\_copyright = action\_process\_file\_info -\> legal\_copyright | filter (action\_process\_image\_name = "rclone.exe" or action\_process\_original\_name ~= "rclone" or action\_process\_company\_name ~= "https\\:\\/\\/rclone\\.org" or action\_process\_description ~= "rclone" or action\_process\_internal\_name ~= "rclone" or action\_process\_legal\_copyright = "The Rclone Authors") and action\_process\_image\_command\_line in ("\*lsd\*", "\*remote:\*", "\*mega\*", "\*--config\*", "\*--auto-confirm\*", "\*or --multi-thread-streams and copy\*", "\*config\*", "\*create\*", "\*user\*", "\*pass\*", "\*progress\*", "\*no-check-certificate\*", "\*ignore-existing\*", "\*auto-confirm\*", "\*multi-thread-streams\*", "\*transfers\*", "\*ftp:\*") | fields \_time, agent\_hostname, agent\_ip\_addresses, actor\_effective\_username, action\_process\_image\_name, action\_process\_image\_path, action\_process\_image\_command\_line, action\_process\_image\_sha256, actor\_process\_image\_name, actor\_process\_image\_path, actor\_process\_command\_line, actor\_process\_image\_sha256, os\_actor\_process\_command\_line | sort desc \_time |

### 8. Shadow Copy Deletion via VSSADMIN

**Technique description:** The query looks for deletion of shadow copies using a specific vssadmin.exe command associated with the BlackSuit encryptor.

#### MITRE ATT\&CK TTP IDs

* T1490 Impact - Inhibit System Recovery

#### XQL Query

config case\_sensitive = false timeframe = 30d | dataset = xdr\_data | filter event\_type = ENUM.PROCESS and event\_sub\_type = ENUM.PROCESS\_START and agent\_os\_type = ENUM.AGENT\_OS\_WINDOWS | filter action\_process\_image\_command\_line ~= "cmd.exe\\s+\\/c\\svssadmin\\sdelete\\sshadows\\s\\/all\\s\\/quiet" or actor\_process\_image\_command\_line ~= "cmd.exe\\s+\\/c\\svssadmin\\sdelete\\sshadows\\s\\/all\\s\\/quiet" | fields \_time, agent\_hostname, agent\_ip\_addresses, actor\_effective\_username, action\_process\_image\_name, action\_process\_image\_path, action\_process\_image\_command\_line, action\_process\_image\_sha256, actor\_process\_image\_name, actor\_process\_image\_path, actor\_process\_command\_line, actor\_process\_image\_sha256, os\_actor\_process\_command\_line, action\_process\_file\_info | sort desc \_time

|-------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 | config case\_sensitive = false timeframe = 30d | dataset = xdr\_data | filter event\_type = ENUM.PROCESS and event\_sub\_type = ENUM.PROCESS\_START and agent\_os\_type = ENUM.AGENT\_OS\_WINDOWS | filter action\_process\_image\_command\_line ~= "cmd.exe\\s+\\/c\\svssadmin\\sdelete\\sshadows\\s\\/all\\s\\/quiet" or actor\_process\_image\_command\_line ~= "cmd.exe\\s+\\/c\\svssadmin\\sdelete\\sshadows\\s\\/all\\s\\/quiet" | fields \_time, agent\_hostname, agent\_ip\_addresses, actor\_effective\_username, action\_process\_image\_name, action\_process\_image\_path, action\_process\_image\_command\_line, action\_process\_image\_sha256, actor\_process\_image\_name, actor\_process\_image\_path, actor\_process\_command\_line, actor\_process\_image\_sha256, os\_actor\_process\_command\_line, action\_process\_file\_info | sort desc \_time |

### 9. BlackSuit Mutex

**Technique description:** The query looks for the mutex created by the BlackSuit encryptor. This mutex is created and checked upon execution to ensure no more than a single encryptor runs at one time.

#### MITRE ATT\&CK TTP ID

* T1027 Execution - Obfuscated Files or Information

#### XQL Query

config case\_sensitive = false timeframe = 30d | dataset = xdr\_data | filter event\_type = ENUM.SYSTEM\_CALL and event\_sub\_type = ENUM.SYSTEM\_CALL\_NT\_CREATE\_MUTANT and agent\_os\_type = ENUM.AGENT\_OS\_WINDOWS | fields agent\_hostname, action\_syscall\_string\_params | alter syscall\_mutant\_name = json\_extract(action\_syscall\_string\_params, "$.1") | alter syscall\_mutant\_name = trim(to\_string(syscall\_mutant\_name),"\\"") | filter syscall\_mutant\_name ~= "WLm87eV1oNRx6P3E4Cy9" | sort desc \_time

|-------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 | config case\_sensitive = false timeframe = 30d | dataset = xdr\_data | filter event\_type = ENUM.SYSTEM\_CALL and event\_sub\_type = ENUM.SYSTEM\_CALL\_NT\_CREATE\_MUTANT and agent\_os\_type = ENUM.AGENT\_OS\_WINDOWS | fields agent\_hostname, action\_syscall\_string\_params | alter syscall\_mutant\_name = json\_extract(action\_syscall\_string\_params, "$.1") | alter syscall\_mutant\_name = trim(to\_string(syscall\_mutant\_name),"\\"") | filter syscall\_mutant\_name ~= "WLm87eV1oNRx6P3E4Cy9" | sort desc \_time |

### 10. BlackSuit Encrypted Files

**Technique description:** The query looks for files encrypted with the .blacksuit file suffix, which indicates the BlackSuit encryptor has encrypted the file.

#### MITRE ATT\&CK TTP ID

* T1486 Impact - Data Encrypted for Impact

#### XQL Query

config case\_sensitive = false timeframe = 30d | dataset = xdr\_data | filter event\_type = ENUM.FILE and action\_file\_extension ~= "blacksuit" | fields agent\_hostname, event\_type, event\_sub\_type, action\_file\_name, action\_file\_path, action\_file\_sha256, action\_file\_md5, actor\_process\_image\_name, actor\_process\_image\_path, actor\_process\_image\_command\_line

|---------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 | config case\_sensitive = false timeframe = 30d | dataset = xdr\_data | filter event\_type = ENUM.FILE and action\_file\_extension ~= "blacksuit" | fields agent\_hostname, event\_type, event\_sub\_type, action\_file\_name, action\_file\_path, action\_file\_sha256, action\_file\_md5, actor\_process\_image\_name, actor\_process\_image\_path, actor\_process\_image\_command\_line |

### 11. BlackSuit Ransom Note

**Technique description:** The query looks for known names of the BlackSuit encryptor's ransomware notes.

#### MITRE ATT\&CK TTP ID

* T1486 Impact - Data Encrypted for Impact

#### XQL Query

config case\_sensitive = false timeframe = 30d | dataset = xdr\_data | filter event\_type = ENUM.FILE and event\_sub\_type = ENUM.FILE\_CREATE\_NEW and action\_file\_name ~= "README.BlackSuit.txt" | fields agent\_hostname, event\_type, event\_sub\_type, action\_file\_name, action\_file\_path, action\_file\_sha256, action\_file\_md5, actor\_process\_image\_name, actor\_process\_image\_path, actor\_process\_image\_command\_line

|---------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 | config case\_sensitive = false timeframe = 30d | dataset = xdr\_data | filter event\_type = ENUM.FILE and event\_sub\_type = ENUM.FILE\_CREATE\_NEW and action\_file\_name ~= "README.BlackSuit.txt" | fields agent\_hostname, event\_type, event\_sub\_type, action\_file\_name, action\_file\_path, action\_file\_sha256, action\_file\_md5, actor\_process\_image\_name, actor\_process\_image\_path, actor\_process\_image\_command\_line |

Back to top

### Tags

* [BlackSuit ransomware](https://unit42.paloaltonetworks.com/tag/blacksuit-ransomware/ "BlackSuit ransomware")
* [Construction](https://unit42.paloaltonetworks.com/tag/construction/ "construction")
* [Education](https://unit42.paloaltonetworks.com/tag/education/ "Education")
* [Extortion](https://unit42.paloaltonetworks.com/tag/extortion/ "Extortion")
* [Ignoble Scorpius](https://unit42.paloaltonetworks.com/tag/ignoble-scorpius/ "Ignoble Scorpius")
* [Leaksite](https://unit42.paloaltonetworks.com/tag/leaksite/ "leaksite")
* [Manufacturing](https://unit42.paloaltonetworks.com/tag/manufacturing/ "Manufacturing")
* [Royal Ransomware](https://unit42.paloaltonetworks.com/tag/royal-ransomware/ "Royal Ransomware")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: FrostyGoop's Zoom-In: A Closer Look into the Malware Artifacts, Behaviors and Network Communications](https://unit42.paloaltonetworks.com/frostygoop-malware-analysis/ "FrostyGoop’s Zoom-In: A Closer Look into the Malware Artifacts, Behaviors and Network Communications")

### Table of Contents

* 

### Related Articles

* [Out of the Crypt: The Evolving Cyber Extortion Economy](https://unit42.paloaltonetworks.com/cyber-extortion-economy/ "article - table of contents")
* [The Golden Scale: Notable Threat Updates and Looking Ahead](https://unit42.paloaltonetworks.com/scattered-lapsus-hunters-updates/ "article - table of contents")
* [Anatomy of an Attack: The "BlackSuit Blitz" at a Global Equipment Manufacturer](https://unit42.paloaltonetworks.com/anatomy-of-an-attack-blacksuit-ransomware-blitz/ "article - table of contents")

## Related Resources

![Pictorial representation of Russian global webmail espionage campaign. A digital illustration of a world map in a network style, highlighting continents with glowing lines and connectivity points in a red and blue theme.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/07/06_Nation-State-cyberattacks_1920x900-1-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) July 23, 2026 [#### Russian Global Webmail Espionage](https://unit42.paloaltonetworks.com/russian-webmail-espionage/)

* [CL-STA-1114](https://unit42.paloaltonetworks.com/tag/cl-sta-1114/ "CL-STA-1114")

* [JavaScript](https://unit42.paloaltonetworks.com/tag/javascript/ "JavaScript")

* [Javascript injection](https://unit42.paloaltonetworks.com/tag/javascript-injection/ "javascript injection")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/russian-webmail-espionage/ "Russian Global Webmail Espionage")  
  ![Pictorial representation of a woman standing in a server room holding a laptop that projects a digital code overlay.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/06_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) May 28, 2026 [#### 2026 World Cup: Discussing The World's Biggest Game's Attack Surface](https://unit42.paloaltonetworks.com/fifa-world-cup-attack-surface/)

* [Fiddling Scorpius](https://unit42.paloaltonetworks.com/tag/fiddling-scorpius/ "Fiddling Scorpius")

* [Fighting Ursa](https://unit42.paloaltonetworks.com/tag/fighting-ursa/ "Fighting Ursa")

* [Muddled Libra](https://unit42.paloaltonetworks.com/tag/muddled-libra/ "Muddled Libra")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/fifa-world-cup-attack-surface/ "2026 World Cup: Discussing The World’s Biggest Game’s Attack Surface")  
  ![Pictoral representation of a man holding a cellphone with a bokeh skyline in the background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/05_Listicle_Category_1505x922-718x440.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) May 27, 2026 [#### Out of the Crypt: The Evolving Cyber Extortion Economy](https://unit42.paloaltonetworks.com/cyber-extortion-economy/)

* [Bling Libra](https://unit42.paloaltonetworks.com/tag/bling-libra/ "Bling Libra")

* [Extortion](https://unit42.paloaltonetworks.com/tag/extortion/ "Extortion")

* [Frontier AI](https://unit42.paloaltonetworks.com/tag/frontier-ai/ "Frontier AI")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/cyber-extortion-economy/ "Out of the Crypt: The Evolving Cyber Extortion Economy")  
  ![Pictorial representation of Iran cyber attacks. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/12_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) April 17, 2026 [#### Threat Brief: Escalation of Cyber Risk Related to Iran (Updated April 17)](https://unit42.paloaltonetworks.com/iranian-cyberattacks-2026/)

* [APK](https://unit42.paloaltonetworks.com/tag/apk/ "APK")

* [DDoS attacks](https://unit42.paloaltonetworks.com/tag/ddos-attacks/ "DDoS attacks")

* [GenAI](https://unit42.paloaltonetworks.com/tag/genai/ "GenAI")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/iranian-cyberattacks-2026/ "Threat Brief: Escalation of Cyber Risk Related to Iran (Updated April 17)")  
  ![Pictorial representation of the APT Boggy Serpens. An illustrated blue snake is highlighted by a red circle against a night sky. The constellation serpens.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/Boggy-Serpens-1920x900-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) March 16, 2026 [#### Boggy Serpens Threat Assessment](https://unit42.paloaltonetworks.com/boggy-serpens-threat-assessment/)

* [Advanced Persistent Threat](https://unit42.paloaltonetworks.com/tag/advanced-persistent-threat/ "Advanced Persistent Threat")

* [Boggy Serpens](https://unit42.paloaltonetworks.com/tag/boggy-serpens/ "Boggy Serpens")

* [C2](https://unit42.paloaltonetworks.com/tag/c2/ "C2")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/boggy-serpens-threat-assessment/ "Boggy Serpens Threat Assessment")  
  ![Pictorial representation of Muddled Libra, aka Scattered Spider. A vibrant illustration of the Libra zodiac sign, featuring a stylized balance scale overlaid with a prominent Libra symbol. The background is a starry night sky with shades of purple and blue, suggesting a cosmic theme.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/03-1-Muddle-Libra-1920x900-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)Threat Actor Groups](https://unit42.paloaltonetworks.com/category/threat-actor-groups/) February 10, 2026 [#### A Peek Into Muddled Libra's Operational Playbook](https://unit42.paloaltonetworks.com/muddled-libra-ops-playbook/)

* [Muddled Libra](https://unit42.paloaltonetworks.com/tag/muddled-libra/ "Muddled Libra")

* [PowerShell](https://unit42.paloaltonetworks.com/tag/powershell/ "PowerShell")

* [Scattered Spider](https://unit42.paloaltonetworks.com/tag/scattered-spider/ "Scattered Spider")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/muddled-libra-ops-playbook/ "A Peek Into Muddled Libra’s Operational Playbook")  
  ![Pictorial representation of a group of individuals discussing an idea with a whiteboard.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/02_Listicle_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) February 3, 2026 [#### Why Smart People Fall For Phishing Attacks](https://unit42.paloaltonetworks.com/psychology-of-phishing/)

* [AI](https://unit42.paloaltonetworks.com/tag/ai/ "AI")

* [Phishing](https://unit42.paloaltonetworks.com/tag/phishing/ "phishing")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/psychology-of-phishing/ "Why Smart People Fall For Phishing Attacks")  
  ![Pictorial representation of threat groups from Russia. The silhouette of a bear and the Ursa constellation inside an orange abstract planet. Abstract, stylized cosmic setting with vibrant blue and purple shapes, representing space and distant planetary bodies.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/01/Ursa-Russia-B-1920x900-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) January 29, 2026 [#### Understanding the Russian Cyberthreat to the 2026 Winter Olympics](https://unit42.paloaltonetworks.com/russian-cyberthreat-2026-winter-olympics/)

* [AI](https://unit42.paloaltonetworks.com/tag/ai/ "AI")

* [IoT](https://unit42.paloaltonetworks.com/tag/iot/ "IoT")

* [Russia](https://unit42.paloaltonetworks.com/tag/russia/ "Russia")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/russian-cyberthreat-2026-winter-olympics/ "Understanding the Russian Cyberthreat to the 2026 Winter Olympics")  
  ![Pictorial representation of RaaS RansomHouse. Digital representation of cybersecurity concept with a padlock superimposed over computer circuit boards, symbolizing data protection and encryption technologies.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/12/06_Ransomware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) December 17, 2025 [#### From Linear to Complex: An Upgrade in RansomHouse Encryption](https://unit42.paloaltonetworks.com/ransomhouse-encryption-upgrade/)

* [ESXi](https://unit42.paloaltonetworks.com/tag/esxi/ "ESXi")

* [Jolly Scorpius](https://unit42.paloaltonetworks.com/tag/jolly-scorpius/ "Jolly Scorpius")

* [RansomHouse](https://unit42.paloaltonetworks.com/tag/ransomhouse/ "RansomHouse")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ransomhouse-encryption-upgrade/ "From Linear to Complex: An Upgrade in RansomHouse Encryption")  
  ![Pictorial representation of 01flip ransomware written in Rust. Digital artwork of a pixelated U.S. dollar bill disintegrating into small blocks against a blue data matrix background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/12/05_Ransomware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) December 10, 2025 [#### 01flip: Multi-Platform Ransomware Written in Rust](https://unit42.paloaltonetworks.com/new-ransomware-01flip-written-in-rust/)

* [Bitcoin](https://unit42.paloaltonetworks.com/tag/bitcoin/ "Bitcoin")

* [CL-CRI-103](https://unit42.paloaltonetworks.com/tag/cl-cri-103/ "CL-CRI-103")

* [Cryptocurrency](https://unit42.paloaltonetworks.com/tag/cryptocurrency/ "Cryptocurrency")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/new-ransomware-01flip-written-in-rust/ "01flip: Multi-Platform Ransomware Written in Rust")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/content/pan/en_US/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
