Blackfield, also styled BlackField, is a financially motivated ransomware and extortion group associated with attacks against manufacturing organizations in Taiwan and Brazil. Its identified victims include Nidec Chaun Choung Technology, the Taiwanese subsidiary of Japan’s Nidec Corporation, and Brazilian footwear manufacturer Redeplast. Its operations combine ransomware encryption with threats to publish or sell stolen information. In June 2026, Blackfield claimed responsibility for an attack against Nidec Chaun Choung Technology that damaged servers and prompted the shutdown of affected systems and networks. The group demanded $2 million to withhold or delete purportedly stolen data, advertised that data for sale for $400,000, and offered paid extensions to its publication deadline. Its extortion model applies financial pressure through ransom demands, threatened disclosure, and the sale of victim information.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a ransomware attack against a Brazilian manufacturing organization.
The Blackfield ransomware leak site lists redeplastrs.com.br as a victim, identifying it as a Brazilian footwear manufacturer. The post provides basic victim metadata and a discovery timestamp but does not state data volume, ransom terms, or proof of compromise.
Conducting a ransomware and data-theft extortion attack against Nidec’s Taiwanese subsidiary, claiming to have stolen 2 TB of data and demanding payment to prevent publication.
Ransomware and double-extortion attack against Nidec's Taiwanese subsidiary, including server compromise, encryption, and claimed data theft with a $2 million extortion demand.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.