RU

BlackMatter

High ConfidenceHigh Threat

DarkSide

BlackMatter is a ransomware-as-a-service (RaaS) affiliate program that emerged in July 2021, believed to be a rebrand of the DarkSide ransomware group. The group incorporated what they claimed to be the 'best features' of DarkSide, REvil, and LockBit. BlackMatter primarily targeted large, high-revenue corporations in the U.S. and Europe with annual revenues over $100 million, demanding ransoms ranging from $80,000 to $15 million in Bitcoin and Monero. The group was known for its double-extortion tactics, which involved both encrypting and exfiltrating victim data. BlackMatter utilized previously compromised credentials for initial access and employed a variety of defense evasion techniques to remain undetected. The group ceased operations in November 2021, citing pressure from law enforcement.

Origin: Russia
Sponsor: Criminal Organization
Active: 2021 - Present
Victims: 100+ organizations
Advanced
Disrupted
Financial Gain
Risk Assessment
79
Composite Risk Score
High Risk
ARCS Compliance80
Escalation Risk78
Grievance Index75
Infrastructure Impact82
History & Evolution

BlackMatter is a ransomware-as-a-service (RaaS) affiliate program that emerged in July 2021, believed to be a rebrand of the DarkSide ransomware group. The group incorporated what they claimed to be the 'best features' of DarkSide, REvil, and LockBit. BlackMatter primarily targeted large, high-revenue corporations in the U.S. and Europe with annual revenues over $100 million, demanding ransoms ranging from $80,000 to $15 million in Bitcoin and Monero. The group was known for its double-extortion tactics, which involved both encrypting and exfiltrating victim data. BlackMatter utilized previously compromised credentials for initial access and employed a variety of defense evasion techniques to remain undetected. The group ceased operations in November 2021, citing pressure from law enforcement.

Targeting

Target Sectors

Critical InfrastructureFood and Agriculture

Target Regions

United StatesEurope
Attribution & Affiliations

Attributed to Criminal Organization (Russia). Attribution confidence: High.

Intelligence Assessment
High
Threat Level
Opportunistic
Targeting
Highly
Adaptability
High
Persistence
Disbanded
Op Tempo
Disbanded
Status

Future Outlook

BlackMatter is expected to continue operations targeting Critical Infrastructure.

Timeline of Key Events
2021
Major

First observed activity

2024
Major

Last known activity