Ransomware Group intelligence
Blackwater
ActiveTrack Blackwater with 17 published victims and 1 known leak locations in a single intelligence view.
Overview
Blackwater is tracked by Breach House as a ransomware group with 17 published victims.
China is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Up checked 3h ago | ejzl7cjxmkx7lzhiqwidmrwtfjv45pkczbc4fnyaut3t7gll3yaiq5id.onion |
Top Activity Sectors (7)
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Blackwater, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: blackwater executes PowerShell scripts to deploy payloads and manipulate system processes.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: blackwater modifies Windows Registry Run keys to establish persistence after initial compromise.
What that means: Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: blackwater disables antivirus tools by terminating security processes and modifying service configurations.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1688 Safe Mode Boot Defense Impairment
What they do: blackwater forces Safe Mode Boot to evade detection by security tools monitoring normal system operations.
What that means: Adversaries may abuse Windows safe mode to disable endpoint defenses.
-
T1070.004 File Deletion Stealth
What they do: blackwater deletes Volume Shadow Copies via vssadmin /delete to prevent file recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1049 System Network Connections Discovery Discovery
What they do: blackwater queries system network connections to map internal infrastructure before targeting.
What that means: Adversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network.
-
T1135 Network Share Discovery Discovery
What they do: blackwater scans network shares using net share commands to identify victim data for encryption.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: blackwater moves laterally through SMB shares to encrypt additional systems within the network.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: blackwater encrypts victim files using a custom ransomware binary targeting critical organizational data.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1491.001 Internal Defacement Impact
What they do: blackwater displays a ransom note and defaces web content on affected NGO and healthcare websites.
What that means: An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems.
Ransom Notes (1)
▼The note this group leaves on a compromised machine. Click a filename to read it.
[rand].decryptme.txt
BLACKWATER Your systems are encrypted. After the attack, your company data has a new extension. We stole confidential data from your infrastructure. BLOG: -If you don't contact us, information about the attack and your details will be published on the blog. DATA: - We have personal data of employees, financial reports and other files from your network. CONSEQUENCES OF THE LEAK: -Financial losses include system restoration costs, fines, downtime, and asset value reduction. These costs exceed expectations and have long-term consequences for the business. -Reputational damage includes loss of trust and media headlines. Reputation restoration requires more resources than system restoration. ALARM: 1. DO NOT modify the files under any circumstances, otherwise the decryption program will not be able to recover your data. 2. DO NOT use third-party (other) software, as it may damage or modify the files. 3. To recover the files, you will need the decryption key or our decryption program. 4. The authorities will not help you, but will only increase your data risks. CONTACT US: Download tor browser -----> Go to domain -----> Enter credentials You can contact us only via our website in the Tor browser. -- Credentials Extension: Df7c2qriCd Domain: 6t5g73fbzdjuhvvovuvuhc4mdgefrwn75szssx4ftqzxyuacdij47pad.onion login: [snip] password: [snip]
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (17)
Search, filter and paginate the victim timeline for Blackwater. Showing 1–17 of 17.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | www.ptesm.com id32068 View details | Portugal | Services | ||
|
www.ptesm.com operates within the Services sector and is situated in the People's Republic of China (PT). The entity's specific business offerings and operational scope are not publicly detailed in verified sources. It is cataloged within this threat-intelligence index as a ransomware victim linked to the blackwater threat actor group. This listing reflects the assessed relationship between the entity and the associated cyber threat without confirming specific incident details. Neutral documentation supports threat-awareness and intelligence aggregation. |
|||||
| Ransomware | www.ptesm.com id32068 View details | Portugal | Services | ||
|
Sinarmas Cepsa Pte. Ltd. is a joint venture between Cepsa and Sinar Mas Group, specializing in the production and marketing of oleochemicals, particularly fatty alcohols and their derivatives |
|||||
| Ransomware | www.amca.org.ar id31725 View details | Argentina | NGOs / Associations | ||
|
The Asociación de Medicina Cardiovascular Argentina, or AMCA, is a non-governmental organization based in Argentina that focuses on cardiovascular medicine. AMCA is involved in various activities related to the promotion of cardiovascular health and education. It is located in Argentina and caters to the needs of the medical community in the country. AMCA was listed as a ransomware victim associated with blackwater. |
|||||
| Ransomware | www.amca.org.ar id31725 View details | Argentina | NGOs / Associations | ||
|
system breach, data blocking |
|||||
| Ransomware | www.shalina.com id31726 View details | India | Healthcare / Pharma | ||
|
Shalina.com is an Indian company operating in the healthcare and pharmaceutical sector. The entity provides various offerings related to healthcare and pharma. It was listed as a ransomware victim associated with Blackwater. |
|||||
| Ransomware | www.shalina.com id31726 View details | India | Healthcare / Pharma | ||
|
system breach, data blocking |
|||||
| Ransomware | msgas.com.br id30847 View details | Brazil | Energy | ||
|
msgas.com.br is a Brazilian company operating in the energy sector, providing various services to its customers. The company is based in Brazil and focuses on delivering energy solutions. msgas.com.br was listed as a ransomware victim associated with blackwater |
|||||
| Ransomware | msgas.com.br id30847 View details | Brazil | Energy | ||
|
customers' personal data, contract information, internal company data: http://ucfhnoihzgx4wz4beyzfxnh46cs37r4zbq627xyctykpatruvmghbyqd.onion/s/7f89713825a4376e/ |
|||||
| Ransomware | txdkj.com id30387 View details | China | Other | ||
|
txdkj.com is a Chinese entity operating in the other sector, providing various offerings. Located in China, the entity serves its purpose in the respective field. txdkj.com was listed as a ransomware victim associated with blackwater |
|||||
| Ransomware | txdkj.com id30387 View details | China | Other | ||
|
Confidential data will be released soon. |
|||||
| Ransomware | www.utourworld.com id29663 View details | Transportation / Travel / Logistics | |||
|
Confidential data will be published soon |
|||||
| Ransomware | medical-park id28087 View details | Türkiye | Healthcare / Pharma | ||
|
Medical Park Hastaneler Grubu is Turkey's leading healthcare group, operating 36 hospitals across 14 provinces with a workforce of 14,000 employees. They offer a wide range of medical services. |
|||||
| Ransomware | Minidoka Memorial Hospital id28321 View details | United States | NGOs / Associations | ||
|
Data will be published after 7 days. |
|||||
| Ransomware | Grupo EBD id28322 View details | Brazil | Transportation / Travel / Logistics | ||
|
All data will be published soon... |
|||||
| Ransomware | Shenzhen Gongjin Electronics id28323 View details | China | Manufacturing / Engineering | ||
|
Shenzhen Gongjin Electronics, founded in 1998 and also known as T&W, is a telecommunications manufacturing company specializing in broadband communication technology. |
|||||
| Ransomware | Compass Housing Alliance id28324 View details | United States | NGOs / Associations | ||
|
Compass Housing Alliance is dedicated to developing and providing essential services, shelter, and affordable housing to ensure that everyone in the community has a safe place to call home. |
|||||
| Ransomware | Tuopu id28325 View details | China | Manufacturing / Engineering | ||
|
Founded in 1983 and headquartered in Ningbo, China, Ningbo Tuopu Group Co., Ltd. is a multipurpose enterprise specializing in R&D, manufacturing, and sales of auto parts |
|||||