"Royal Ransomware Gang Adds BlackSuit Encryptor to Their Arsenal"

The Royal ransomware gang is testing a new encryptor called "BlackSuit," similar to the operation's standard encryptor. Royal started in January 2023, and is suspected to be the direct successor to the Conti operation, which shut down in June 2022. Royal ransomware has become one of the most active operations, responsible for several attacks on businesses. There have been talks since late April that the Royal ransomware operation was preparing to rebrand under a new name. The group began to feel pressure from law enforcement following their attack on the City of Dallas, Texas. In May, researchers found a new BlackSuit ransomware campaign that used its own branded encryptor and Tor negotiation sites. This was thought to be the ransomware operation that the Royal ransomware group would rebrand as. However, no rebranding occurred, and Royal is still operating while using BlackSuit in limited attacks. This article continues to discuss the Royal ransomware gang testing the BlackSuit encryptor. 

Bleeping Computer reports "Royal Ransomware Gang Adds BlackSuit Encryptor to Their Arsenal"

Submitted by Anonymous on