BleepingComputer found evidence that after the clamorous Colonia Pipeline attack, the DarkSide ransomware gang has rebranded as a new BlackMatter ransomware operation. The experts analyzed encryption algorithms in a decryptor used by BlackMatter, which is actively attacking corporate entities.
BleepingComputer became aware of a victim that paid a $4 million ransom to BlackMatter gang. The company received by the cybercriminals gang both Windows and Linux ESXi decryptors.
BleepingComputer shared a decryptor from a BlackMatter victim with Emisosft CTO Fabian Wosar who confirmed that the new ransomware gang is using the same unique encryption methods (a custom implementation of Salsa20 matrix) implemented by the DarkSide.
DarkSide also used an RSA-1024 implementation unique to their encryptor, which is the same used by BlackMatter.
The above and other similarities, such as the similar text on the leak sites, suggest that BlackMatter rebrand from DarkSide.
On its leak site BlackMatter states that it doesn’t attack:
Follow me on Twitter: @securityaffairs and Facebook
[adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – hacking, BlackMatter)
[adrotate banner=”5″]
[adrotate banner=”13″]
US seeks to seize $7.74M in crypto linked to North Korean fake IT worker schemes,…
OpenAI banned ChatGPT accounts tied to Russian and Chinese hackers using the tool for malware,…
A new variant of the Mirai botnet exploits CVE-2024-3721 to target DVR systems, using a…
BadBox 2.0 malware has infected millions of IoT devices globally, creating a botnet used for…
A supply chain attack hit NPM, threat actors compromised 16 popular Gluestack packages, affecting 950K+…
Security Affairs Malware newsletter includes a collection of the best articles and research on malware…
This website uses cookies.