BlackMatter is a ransomware family and ransomware-as-a-service operation that emerged in July 2021 and announced its shutdown in November 2021. It targeted large corporations, recruiting affiliates and initial access providers with access to organizations generating more than $100 million in annual revenue. Despite publicly prohibiting attacks on critical infrastructure, the operation attacked organizations in the food and agriculture sector and blood testing facilities.
BlackMatter primarily targeted Windows systems, with Linux encryptors also observed in August 2021. It uses partial file encryption to accelerate attacks and incorporates anti-analysis techniques, including API hashing and anti-debugging. Its Windows implementation uses WMI to delete volume shadow copies, hindering recovery. Embedded configuration controls encryption exclusions and ransom-note behavior; versions 1.9 and later can attempt to print ransom notes through available printers. The malware encrypts victim information transmitted to command-and-control infrastructure. BlackMatter campaigns also used the ExMatter data-exfiltration tool to support extortion through data theft.
BlackMatter has substantial technical and operational continuity with DarkSide, including nearly identical early payloads, similar affiliate structures, and overlapping targeting policies. The FBI subsequently linked ALPHV/BlackCat developers and money launderers to DarkSide and BlackMatter, without conclusively establishing a direct organizational rebrand. After BlackMatter shut down, some affiliates moved victims to LockBit 2.0. During its operation, a cryptographic flaw allowed Emsisoft and trusted partners to recover victims' files without ransom payment; a later BlackMatter update fixed that flaw.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
ProxyShell is identified as the chain of CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207, actively exploited by ransomware groups including LockBit and BlackMatter. | Ransomware groups including LockBit and BlackMatter exploited it actively.
CVE-2021-34523 is listed as a component of ProxyShell, an Exchange exploit chain actively used by LockBit and BlackMatter. | Ransomware groups including LockBit and BlackMatter exploited it actively.
CVE-2021-31207 is listed alongside CVE-2021-34473 and CVE-2021-34523 in the historically exploited ProxyShell chain. | Ransomware groups including LockBit and BlackMatter exploited it actively.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
BlackMatter had significant overlaps with the DarkSide operation, including similarities in its malware code, public code of conduct, and affiliate structure.
À Darkside succède le RaaS BlackMatter, qui disparaît à son tour en novembre 2021.
At least one affiliate of the BlackMatter ransomware operation has begun using a custom data exfiltration tool in its attacks.
ELBRUS retired the DarkSide ransomware ecosystem in May 2021 and released its successor, BlackMatter, in July 2021.
36 distinct techniques documented for this family, organized by ATT&CK tactic.
The advertiser was looking to recruit parties who could provide access to corporate networks of companies with more than $100,000,000 yearly revenue. This is a common practice for ransomware-as-a-service operations... In this particular case, the BlackMatter user was looking to recruit initial access providers and brokers.
Attempts to log in using credentials from its configuration list to determine if the compromised system is a part of the domain admin that it will use for later routines
the built-in local administrator account being enabled and set for automatic sign in
Performs a 32-bit or 64-bit shellcode injection to elevate its token... LockBit 3.0 is capable of injecting a DLL into memory via reflective loading
Attempts to log in using credentials from its configuration list to determine if the compromised system is a part of the domain admin that it will use for later routines
the built-in local administrator account being enabled and set for automatic sign in
This specific sample is a PowerShell script containing two layers of obfuscated code... The strings it uses are decrypted using a simple bitwise-XOR routine, a bitwise-XOR and NOT routine, or a decryption routine involving a linear congruential generator (LCG) algorithm
BlackMatter also has an encrypted configuration inside the binary, located in a fake PE resource section.
This communication was observed as impersonating the following user-agent strings that may be anomalous in some environments
Performs a 32-bit or 64-bit shellcode injection to elevate its token... LockBit 3.0 is capable of injecting a DLL into memory via reflective loading
Prior to file encryption, BlackMatter wipes the recycle bin folder of every drive on the system... Once found, the folders and their contents are recursively deleted using DeleteFileW.
Attempts to log in using credentials from its configuration list to determine if the compromised system is a part of the domain admin that it will use for later routines
By targeting virtual machines, ransomware operators can also encrypt multiple servers at once with a single command. In June, researchers spotted a new REvil ransomware Linux encryptor designed to target VMware ESXi virtual machines, a popular enterprise virtual machine platform.
LockBit 3.0 also checks the victim machine’s UI language to avoid infecting machines with these languages...
Technique System Service Discovery [T1007] Procedure BlackMatter uses EnumServicesStatusExW to enumerate running services on the network.
the malware calls NtQuerySystemInformation to query information about processes on the system. For each process entry, it checks if the process’s name is explorer.exe...
The victim sends a beacon including the machine name, OS version and CPU architecture, OS language, username, domain name, disk sizes
Encrypts network shares and Exchange Mailbox if set in its configuration flag
By targeting virtual machines, ransomware operators can also encrypt multiple servers at once with a single command. In June, researchers spotted a new REvil ransomware Linux encryptor designed to target VMware ESXi virtual machines, a popular enterprise virtual machine platform.
Knowing DarkSide’s past mistakes, we were surprised when BlackMatter introduced a change to their ransomware payload that allowed us to once again recover victims’ data without the need for a ransom to be paid. | Emsisoft researchers discovered a critical flaw in the BlackMatter ransomware that allowed them to help victims recover their files without paying a ransom.
we have confirmed the values of the following BlackCat’s configuration fields completely match BlackMatter’s. kill_services kill_processes
LockBit 3.0’s deletion of shadow copies is clearly lifted from BlackMatter’s code, as this is performed using Windows Management Instrumentation (WMI) through COM objects, as opposed to LockBit 2.0’s use of vssadmin.exe.
BlackMatter changes the background image, a common practice among ransomware creators.
106 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
114 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named ransomware referenced through its associated group’s historical exploitation of the ProxyShell vulnerability chain. It appears only as a comparison with earlier Exchange threats, with no stated connection to CVE-2026-96940.
BlackMatter is mentioned only as background in the lineage/rebranding of another ransomware operation.
Ransomware-as-a-Service family targeting business users and large enterprises. It encrypts files using Salsa20 + RSA-1024, appends a random extension, drops README ransom notes, can change desktop wallpaper, supports Windows Safe Mode execution, and the operators claim data theft and double extortion.
Mentioned only as another malware family known to use a similar user account control bypass.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.