BlackSuit Ransomware Group
View MITRE Group Page ↗Key Facts
- Attributed Country: Russian Federation.
- ATT&CK Group Reference: G1025 (BlackSuit Ransomware Group).
- Linked to 1 primary court prosecution records.
- Identified 0 individually charged operatives.
Primary ATT&CK Techniques Employed
| Technique | Frequency |
|---|---|
| T1078 Valid Accounts | 1 incidents |
| T1486 Data Encrypted for Impact | 1 incidents |
| T1490 Inhibit System Recovery | 1 incidents |
Prosecution Cases Attributed to This Actor
CDK Global BlackSuit Ransomware Incident
Destructive ransomware incident that incapacitated CDK Global, the premier SaaS dealer management platform for approximately 15,000 car dealerships across North America. Attackers deployed BlackSuit ransomware throughout CDK cloud and on-premises data centers, forcing dealership employees into pen-and-paper workarounds for weeks until an estimated $25 million ransom was transferred.
Targeted Defensive Hardening for BlackSuit Ransomware Group
Primary Initial Access Defense
Enforce hardware FIDO2 multi-factor authentication across all perimeter VPN, Citrix, and cloud data portals. Prohibit SMS or push-based MFA that can be bypassed via vishing or SIM swapping.
Lateral Movement Interception
Restrict internal SMB (port 445) and RPC traversal between workstation subnets. Implement tiered Active Directory administration so domain administrator credentials are never cached on endpoints.