BlackMatter Ransomware Gang is Actively Looking for Affiliates, Attacks are Imminent

While some ransomware gangs are shutting down their servers, others are planning to make their first steps in the lucrative world of cybercrime. Recently, high-profile ransomware gangs like the DarkSide and REvil Ransomware ended their operations. However, the hole they left behind has been quickly filled out by a competing ransomware gang going by the name BlackMatter. The criminals behind the BlackMatter Ransomware are advertising their product on underground hacking forums, which were previously used by the REvil and DarkSide Ransomware gangs. However, there is not enough information to determine whether the new gang is sharing code, members, or infrastructure with other notable ransomware campaigns.

BlackMatter Ransomware Plans to Target Companies in the US, UK, Australia, and Canada

The author of the threads promoting BlackMatter Ransomware claims that this product combines the best features of the REvil and DarkSide Ransomware. They also state that they are looking for victims in specific regions – the United States, United Kingdom, Australia, and Canada. They are looking to work with cybercriminals who have already managed to compromise the networks of large organizations or companies. Allegedly, they are offering bounties up to $100,000 in exchange for access to these networks. This is not a new strategy, and other ransomware gangs have looked for such affiliate services in the past.

The criminals behind the BlackMatter Ransomware are looking to infect between 500 and 15,000 hosts in the compromised network, and they emphasize the fact that they are only looking for new victims. They refuse to infect companies that were previously affected by ransomware attacks.

While no victims of the BlackMatter Ransomware have been identified yet, the file-encryption Trojan is likely to be incredibly dangerous and flexible. Allegedly, it is able to compromise a wide range of operating systems and devices running on Linux or Windows. They also support encryption for network-attached storage (NAS) devices.

BlackMatter Gang Combines Two Types of Extortion

The crooks have already set up a site meant to be used for data leaks, showing that the criminals are planning to steal data prior to encrypting it. Victims who do not accept to pay a ransom fee will not receive a decryptor, and their information will be published online.

The criminals are also refusing to work with companies and organizations belonging to particular sectors – healthcare, oil industry, defense, government, and non-profit organizations. We are yet to see whether the BlackMatter Ransomware is all talk and no action.

July 29, 2021
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.