BlackSuit Ransomware: Extortion Sites Seized in Operation Checkmate
Royal Ransomware Rebrands as BlackSuit, demanding Over $500 Million
Table of Contents
Royal ransomware, a notorious cybercriminal group, has reportedly rebranded as BlackSuit, continuing its malicious activities under a new guise. the FBI and CISA confirmed this shift in August 2024, revealing that the group has extorted over $500 million from victims since its emergence more than two years ago.
The Evolution of a Threat: From Royal to BlackSuit
the cybersecurity landscape is constantly evolving,and unfortunatly,so are the tactics of ransomware gangs. A significant advancement in this ongoing battle is the apparent rebranding of the Royal ransomware operation to BlackSuit. This transition, confirmed by the FBI and Cybersecurity and Infrastructure Security Agency (CISA) in August 2024, signals a continued threat from a group that has been actively targeting organizations worldwide.
Evidence pointing to this rebranding emerged as early as November 2023. A joint advisory issued by the FBI and CISA highlighted striking similarities between the Royal and BlackSuit ransomware strains. The advisory detailed how both groups employed comparable tactics, techniques, and procedures (TTPs). More tellingly, the encryptors used by royal and BlackSuit exhibited clear and undeniable coding overlaps, strongly suggesting a shared origin or a direct lineage.
A Trail of Devastation: Royal’s impact
Before the BlackSuit rebranding came to light, the Royal ransomware gang had already established a formidable and destructive presence. As September 2022, the group was linked to attacks impacting over 350 organizations globally. The financial demands made by Royal were staggering, with ransom demands collectively exceeding $275 million.this figure underscores the significant financial damage and disruption caused by their operations.
BlackSuit’s Escalating Demands
Following the confirmed rebranding, the scale of the threat has only amplified. The FBI and CISA’s August 2024 confirmation revealed that the BlackSuit operation, essentially the continuation of Royal, had escalated its demands. The total ransom demands from victims as the group’s initial emergence now surpass a staggering $500 million. This considerable increase in demanded funds reflects the group’s continued ambition and perceived success in its illicit activities.
Seizing the Means of Extortion
In a significant development on July 24, 2025, authorities announced that not only were the ransomware operations disrupted, but the negotiation sites used by the BlackSuit group were also seized. This action represents a crucial step in dismantling the infrastructure that facilitates these cybercrimes,aiming to hinder the group’s ability to communicate with victims and collect ransoms.
The ongoing evolution of ransomware groups like Royal/BlackSuit serves as a stark reminder of the persistent threat posed by cybercriminals. organizations must remain vigilant, implementing robust cybersecurity measures, staying informed about emerging threats, and preparing for potential attacks. The fight against ransomware is a continuous effort, requiring collaboration between law enforcement, cybersecurity professionals, and the organizations they protect.
