History
2025: Destruction of Grouping
In mid-August 2024, US law enforcement agencies reported the destruction of the key infrastructure of the cybercriminal group BlackSuit. The attackers were distributing ransomware, and the number of victims exceeded 450 organizations.
The BlackSuit group, which was previously called Royal, appeared in 2022. She is responsible for dozens of high-profile attacks that have caused significant damage to various companies and government agencies. In particular, the attackers organized a large-scale cyber attack on the IT infrastructure of Dallas, as a result of which city emergency services, the judicial system and various government organizations were affected. BlackSuit has claimed responsibility for dozens of attacks on American elementary schools and colleges, as well as prominent companies and local authorities. The total ransom received by BlackSuit participants exceeded $370 million. In some cases, attackers demanded up to $60 million from victims of attacks.
In the| Constant cyber attacks by the BlackSuit group, which spreads the ransomware virus, on critical US infrastructure pose a serious threat to public safety, said Assistant Attorney General for National Security John Eisenberg. |
The operation to eliminate the BlackSuit infrastructure was called Checkmate. Its coordinator was Europol, and law enforcement agencies, Germany France Britain and other countries took part in operational activities. In particular, the sites of cybercriminals on the darknet were liquidated. However, according to Cisco Talos, BlackSuit attackers have formed a new ransomware group called Chaos. [1]
