BlackField is a ransomware and extortion threat actor that emerged publicly by at least October 2023 and was later observed conducting ransomware operations in 2026. The group has claimed intrusions involving theft of sensitive data and has used public leak-and-pressure tactics characteristic of double extortion, combining ransomware deployment with threats to publish or sell stolen information. BlackField has been linked to attacks against organizations in Taiwan and Brazil, including a Taiwanese manufacturing subsidiary of Japan-based Nidec Corporation and a Brazilian footwear manufacturer. In the Nidec incident, BlackField claimed to have compromised the victim’s IT environment, stolen a large volume of corporate data, and demanded payment to prevent publication. The group also advertised the stolen dataset for sale and offered paid delays to postpone release, indicating a structured extortion model centered on both encryption and exfiltration. Observed behavior attributed to BlackField includes initial compromise of victim environments, data theft, ransomware-related disruption, and post-compromise extortion. Reported techniques and effects include use of valid accounts, exfiltration, encryption for impact, and actions consistent with inhibiting recovery. The actor has also published sample materials to support extortion claims and increase pressure on victims. Separate reporting from October 2023 associated the name blackfield with a claim of possessing personal data belonging to Israeli military and security personnel, suggesting either opportunistic politically themed data-leak activity or overlap between ransomware branding and broader intrusion claims. High-confidence attribution beyond the claim itself is not available. BlackField is best characterized as a financially motivated ransomware actor using double-extortion tactics against corporate targets, with observed victimology including manufacturing-related organizations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a ransomware attack against a Brazilian manufacturing organization.
Conducting a ransomware and data-theft extortion attack against Nidec’s Taiwanese subsidiary, claiming to have stolen 2 TB of data and demanding payment to prevent publication.
Ransomware and double-extortion attack against Nidec's Taiwanese subsidiary, including server compromise, encryption, and claimed data theft with a $2 million extortion demand.
Conducting a ransomware and data-extortion attack against Nidec Corporation and its Taiwanese subsidiary, demanding $2 million, threatening to publish or sell allegedly stolen data, leaking sample files as proof, and offering deadline extensions for payment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.