The Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the National Security Agency (NSA) released a joint advisory detailing the activity of the ransomware group BlackMatter. BlackMatter is considered to likely be a reorganization of the DarkSide group, which was active from September 2020 to May 2021. The group’s activity began in July 2021 and includes ransom payment demands ranging from $80,000 to $20,000,000 targeting many USA based companies.
The CISA advisory includes analysis and IOCs of one BlackMatter variant (Virustotal link below). BlackMatter obtains user or admin credentials from a prior compromise and then enumerates running processes and services. It then utilizes LDAP and SMB to enumerate AD hosts as well as network shares using the TTPs listed in the table below. The SMB protocol is utilized to remotely encrypt all accessible shares from the original compromised host.
The Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the National Security Agency (NSA) released a joint advisory detailing the activity of the ransomware group BlackMatter. BlackMatter is considered to likely be a reorganization of the DarkSide group, which was active from September 2020 to May 2021. The group’s activity began in July 2021 and includes ransom payment demands ranging from $80,000 to $20,000,000 targeting many USA based companies.
The CISA advisory includes analysis and IOCs of one BlackMatter variant (Virustotal link below). BlackMatter obtains user or admin credentials from a prior compromise and then enumerates running processes and services. It then utilizes LDAP and SMB to enumerate AD hosts as well as network shares using the TTPs listed in the table below. The SMB protocol is utilized to remotely encrypt all accessible shares from the original compromised host.
