BlackMatter was a ransomware-as-a-service operation that emerged in July 2021 and is widely assessed as a successor or rebrand of DarkSide, with some reporting also noting overlaps in tradecraft and ecosystem relationships with REvil and later BlackCat/ALPHV. The group operated as a big-game-hunting criminal enterprise focused on large organizations, typically seeking access to companies with annual revenue above $100 million and recruiting initial access brokers, penetration testers, and affiliates on Russian-language underground forums. BlackMatter publicly claimed to avoid certain sectors, including healthcare, government, and parts of critical infrastructure, but it was nevertheless linked to attacks affecting U.S. critical infrastructure entities, including organizations in blood testing and food and agriculture. BlackMatter targeted primarily Windows enterprise environments and also developed Linux tooling, including an ESXi-focused encryptor for VMware virtualized infrastructure. Its Windows ransomware used multithreaded encryption, partial encryption in some variants, native Windows cryptographic functionality, dynamic API resolution, string obfuscation, anti-debugging, and privilege escalation via ICMLuaUtil-based UAC bypass. Reported capabilities included shadow copy deletion, process and service termination, recycle-bin wiping, persistence through autorun mechanisms, safe-mode reboot support, network-share encryption, Active Directory and domain-controller awareness, and in some analyses attempted domain-wide propagation through enterprise administration mechanisms. BlackMatter also supported configurable victim-specific payloads and could transmit victim metadata and encryption statistics to remote infrastructure. The operation employed double-extortion tactics, combining file encryption with data theft and leak-site pressure. BlackMatter was associated with Exmatter, a custom exfiltration tool designed to selectively steal high-value business data before ransomware deployment. The group maintained a leak site and used stolen-data exposure as leverage during negotiations. Reporting also indicates the operators reserved the right to take over affiliate negotiations directly, reflecting tight operator control within the RaaS model. Technical and operational links to DarkSide were strong: early BlackMatter payloads were described as nearly identical to late DarkSide versions, and researchers identified distinctive shared encryption routines. BlackMatter itself later became part of the lineage commonly associated with BlackCat/ALPHV, whether through direct succession, affiliate migration, or shared tooling and operators. After BlackMatter ceased operations, some victims were reportedly transferred to LockBit infrastructure, underscoring the fluidity of the ransomware ecosystem.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
57 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
72 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a successor branding of DarkSide.
RaaS/extortion group operating BlackMatter ransomware against large enterprises, using double extortion, recruiting initial access brokers, and targeting high-revenue corporate networks globally.
Mentioned as a comparison and in discussion of possible operational similarities with BlackCat.
Mentioned as another threat actor associated with use of the same UAC bypass technique referenced in the SilabRAT analysis.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.