Ransomware Group intelligence
Blackmatter
InactiveTrack Blackmatter with 32 published victims and 1 known leak locations in a single intelligence view.
Overview
Blackmatter is tracked by Breach House as a ransomware group with 32 published victims.
United States is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Down checked 1h ago | blackmax7su6mbwtcyo3xwtpfxpm356jjqrs34y4crcytpw7mifuedyd.onion |
Top Activity Sectors (9)
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Blackmatter, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: blackmatter executes PowerShell commands to run payload scripts and perform initial system modifications.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: blackmatter adds malicious registry run keys to maintain persistence across reboots.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: blackmatter disables antivirus and monitoring tools using registry and service manipulation to ensure persistence.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: blackmatter encrypts and encodes its own payload files to evade static detection.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1070.004 File Deletion Stealth
What they do: blackmatter deletes Volume Shadow Copies and backup locations via command-line tools to prevent recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1049 System Network Connections Discovery Discovery
What they do: blackmatter queries system network connections to identify hosts for targeted encryption.
What that means: Adversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network.
-
T1135 Network Share Discovery Discovery
What they do: blackmatter uses network share discovery to locate victim file shares and staging directories for encryption targets.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: blackmatter moves laterally through SMB/Windows Admin Shares to compromise additional systems.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: blackmatter encrypts victim files and backups using its ransomware payload to maximize impact.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1491.001 Internal Defacement Impact
What they do: blackmatter performs internal defacement by replacing victim files with ransom notes and altered content.
What that means: An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems.
Tools Observed (1)
▼Software Blackmatter has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Exfiltration
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Crypto Wallets (1)
▼| Address | Chain | Received (USD) | Payments |
|---|---|---|---|
bc1q2855268hg3lm34qwk5jvnnjm762ef8rkdvyjez |
bitcoin | $4,070,929 | 2 |
Crowdsourced payment data from Ransomwhere, licensed CC BY 4.0. Figures are what has been reported and attributed to this family, not a confirmed total. Cite as: Cable, Jack. (2024). Ransomwhere: A Crowdsourced Ransomware Payment Dataset (1.1.0) [Data set]. Zenodo. https://doi.org/10.5281/zenodo.6512122
Ransom Notes (1)
▼The note this group leaves on a compromised machine. Click a filename to read it.
blackmatter.txt
~+
* +
' BLACK |
() .-.,='``'=. - o -
'=/_ \ |
* | '=._ |
\ `=./`, '
. '=.__.=' `=' *
+ Matter +
O * ' .
>>> What happens?
Your network is encrypted, and currently not operational.
We need only money, after payment we will give you a decryptor for the entire network and you will restore all the data.
>>> What guarantees?
We are not a politically motivated group and we do not need anything other than your money.
If you pay, we will provide you the programs for decryption and we will delete your data.
If we do not give you decrypters or we do not delete your data, no one will pay us in the future, this does not comply with our goals.
We always keep our promises.
>>> How to contact with us?
1. Download and install TOR Browser (https://www.torproject.org/).
2. Open http://supp24yy6a66hwszu2piygicgwzdtbwftb76htfj7vnip3getgqnzxid.onion/[snip].
>>> Warning! Recovery recommendations.
We strongly recommend you to do not MODIFY or REPAIR your files, that will damage them.
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (32)
Search, filter and paginate the victim timeline for Blackmatter. Showing 1–32 of 32.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | National Beverage id1779 View details | United States | Hospitality / Food & Beverage / Tourism | — | |
|
No additional victim description available. |
|||||
| Ransomware | Keycentrix id1778 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Jobbers Meat Packing Co., Inc. id1777 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Home State Bank id1776 View details | Finance / Legal / Insurance | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Armour Transportation Systems id1775 View details | Transportation / Travel / Logistics | — | ||
|
No additional victim description available. |
|||||
| Ransomware | ZKTeco USA id1514 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | crystalvalley id1481 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Bumper to Bumper Autoparts id1420 View details | Manufacturing / Engineering | — | ||
|
No additional victim description available. |
|||||
| Ransomware | LA-Martiniquaise id1418 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | JMclaughlin id1416 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | CasagrandeGroup id1415 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | BCP Securities id1414 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Pramer Baustoffe GmbH id1412 View details | Communication / Marketing | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Ellerboeck id1411 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Citrocasa GmbH id1410 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Actief-Jobmade id1409 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Eisvogel Hubert Bernegger GmbH id1404 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Pulmuone Co., Ltd. id1388 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Modern Testing Services id1386 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | northwoods & spectrumfurniture id1383 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | EQUITY TRANSPORTATION id1379 View details | Transportation / Travel / Logistics | — | ||
|
No additional victim description available. |
|||||
| Ransomware | River City Construction id1356 View details | Construction / Real Estate | — | ||
|
No additional victim description available. |
|||||
| Ransomware | hhcp.com id1217 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Network Telecom / Enreach id1216 View details | Telecommunications | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Pine Labs Pvt id1215 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Kaydon Corporation (SKF Group Brand) id1214 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | tastefulselections & WFG id1213 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Middleton Reutlinger id1212 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | g-able.com id1211 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Diamond Schmitt id1210 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Trust Capital Funding id1209 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Olympus id688 View details | United States | Other | — | |
|
No additional victim description available. |
|||||