Deprecated: Creation of dynamic property WC_Product_Advanced_Ad::$product_type is deprecated in /home/mindksdy/defiprofitboost.com/wp-content/plugins/advanced-ads-selling/classes/WooCommerce-product.php on line 14

Deprecated: Creation of dynamic property Advanced_Ads_Pro_Module_Cache_Busting::$lazy_load_module_enabled is deprecated in /home/mindksdy/defiprofitboost.com/wp-content/plugins/advanced-ads-pro/modules/cache-busting/cache-busting.class.php on line 92

Deprecated: Creation of dynamic property Advanced_Ads_Pro_Module_Cache_Busting::$lazy_load_module_offset is deprecated in /home/mindksdy/defiprofitboost.com/wp-content/plugins/advanced-ads-pro/modules/cache-busting/cache-busting.class.php on line 93

Deprecated: Creation of dynamic property Advanced_Ads_Pro_Module_Cache_Busting::$cache_busting_module_enabled is deprecated in /home/mindksdy/defiprofitboost.com/wp-content/plugins/advanced-ads-pro/modules/cache-busting/cache-busting.class.php on line 99

Deprecated: Creation of dynamic property Advanced_Ads_Pro_Module_Cache_Busting::$fallback_method is deprecated in /home/mindksdy/defiprofitboost.com/wp-content/plugins/advanced-ads-pro/modules/cache-busting/cache-busting.class.php on line 115

Deprecated: Creation of dynamic property Advanced_Ads_Pro_Cache_Busting_Server_Info::$cache_busting is deprecated in /home/mindksdy/defiprofitboost.com/wp-content/plugins/advanced-ads-pro/modules/cache-busting/server-info.class.php on line 15

Deprecated: Creation of dynamic property Advanced_Ads_Pro_Cache_Busting_Server_Info::$options is deprecated in /home/mindksdy/defiprofitboost.com/wp-content/plugins/advanced-ads-pro/modules/cache-busting/server-info.class.php on line 16

Deprecated: Creation of dynamic property Advanced_Ads_Pro_Cache_Busting_Server_Info::$server_info_duration is deprecated in /home/mindksdy/defiprofitboost.com/wp-content/plugins/advanced-ads-pro/modules/cache-busting/server-info.class.php on line 18

Deprecated: Creation of dynamic property Advanced_Ads_Pro_Cache_Busting_Server_Info::$vc_cache_reset is deprecated in /home/mindksdy/defiprofitboost.com/wp-content/plugins/advanced-ads-pro/modules/cache-busting/server-info.class.php on line 19

Deprecated: Creation of dynamic property Advanced_Ads_Pro_Cache_Busting_Server_Info::$is_ajax is deprecated in /home/mindksdy/defiprofitboost.com/wp-content/plugins/advanced-ads-pro/modules/cache-busting/server-info.class.php on line 21

Deprecated: Creation of dynamic property Advanced_Ads_Pro_Cache_Busting_Server_Info_Cookie::$server_info is deprecated in /home/mindksdy/defiprofitboost.com/wp-content/plugins/advanced-ads-pro/modules/cache-busting/server-info.class.php on line 143

Deprecated: Creation of dynamic property Advanced_Ads_Pro_Module_Cache_Busting::$server_info is deprecated in /home/mindksdy/defiprofitboost.com/wp-content/plugins/advanced-ads-pro/modules/cache-busting/cache-busting.class.php on line 117

Deprecated: Creation of dynamic property CSF_Field_typography::$field is deprecated in /home/mindksdy/defiprofitboost.com/wp-content/plugins/cryptocurrency-donation-box/admin/codestar-framework/classes/fields.class.php on line 14

Deprecated: Creation of dynamic property CSF_Field_typography::$unique is deprecated in /home/mindksdy/defiprofitboost.com/wp-content/plugins/cryptocurrency-donation-box/admin/codestar-framework/classes/fields.class.php on line 16

Deprecated: Creation of dynamic property CSF_Field_typography::$where is deprecated in /home/mindksdy/defiprofitboost.com/wp-content/plugins/cryptocurrency-donation-box/admin/codestar-framework/classes/fields.class.php on line 17

Deprecated: Creation of dynamic property CSF_Field_typography::$parent is deprecated in /home/mindksdy/defiprofitboost.com/wp-content/plugins/cryptocurrency-donation-box/admin/codestar-framework/classes/fields.class.php on line 18

Deprecated: Creation of dynamic property CSF_Field_typography::$field is deprecated in /home/mindksdy/defiprofitboost.com/wp-content/plugins/cryptocurrency-donation-box/admin/codestar-framework/classes/fields.class.php on line 14

Deprecated: Creation of dynamic property CSF_Field_typography::$unique is deprecated in /home/mindksdy/defiprofitboost.com/wp-content/plugins/cryptocurrency-donation-box/admin/codestar-framework/classes/fields.class.php on line 16

Deprecated: Creation of dynamic property CSF_Field_typography::$where is deprecated in /home/mindksdy/defiprofitboost.com/wp-content/plugins/cryptocurrency-donation-box/admin/codestar-framework/classes/fields.class.php on line 17

Deprecated: Creation of dynamic property CSF_Field_typography::$parent is deprecated in /home/mindksdy/defiprofitboost.com/wp-content/plugins/cryptocurrency-donation-box/admin/codestar-framework/classes/fields.class.php on line 18

Deprecated: Creation of dynamic property CSF_Field_color::$field is deprecated in /home/mindksdy/defiprofitboost.com/wp-content/plugins/cryptocurrency-donation-box/admin/codestar-framework/classes/fields.class.php on line 14

Deprecated: Creation of dynamic property CSF_Field_color::$value is deprecated in /home/mindksdy/defiprofitboost.com/wp-content/plugins/cryptocurrency-donation-box/admin/codestar-framework/classes/fields.class.php on line 15

Deprecated: Creation of dynamic property CSF_Field_color::$unique is deprecated in /home/mindksdy/defiprofitboost.com/wp-content/plugins/cryptocurrency-donation-box/admin/codestar-framework/classes/fields.class.php on line 16

Deprecated: Creation of dynamic property CSF_Field_color::$where is deprecated in /home/mindksdy/defiprofitboost.com/wp-content/plugins/cryptocurrency-donation-box/admin/codestar-framework/classes/fields.class.php on line 17

Deprecated: Creation of dynamic property CSF_Field_color::$parent is deprecated in /home/mindksdy/defiprofitboost.com/wp-content/plugins/cryptocurrency-donation-box/admin/codestar-framework/classes/fields.class.php on line 18

Deprecated: Creation of dynamic property CSF_Field_typography::$field is deprecated in /home/mindksdy/defiprofitboost.com/wp-content/plugins/cryptocurrency-donation-box/admin/codestar-framework/classes/fields.class.php on line 14

Deprecated: Creation of dynamic property CSF_Field_typography::$unique is deprecated in /home/mindksdy/defiprofitboost.com/wp-content/plugins/cryptocurrency-donation-box/admin/codestar-framework/classes/fields.class.php on line 16

Deprecated: Creation of dynamic property CSF_Field_typography::$where is deprecated in /home/mindksdy/defiprofitboost.com/wp-content/plugins/cryptocurrency-donation-box/admin/codestar-framework/classes/fields.class.php on line 17

Deprecated: Creation of dynamic property CSF_Field_typography::$parent is deprecated in /home/mindksdy/defiprofitboost.com/wp-content/plugins/cryptocurrency-donation-box/admin/codestar-framework/classes/fields.class.php on line 18

Deprecated: Creation of dynamic property CSF_Field_typography::$field is deprecated in /home/mindksdy/defiprofitboost.com/wp-content/plugins/cryptocurrency-donation-box/admin/codestar-framework/classes/fields.class.php on line 14

Deprecated: Creation of dynamic property CSF_Field_typography::$unique is deprecated in /home/mindksdy/defiprofitboost.com/wp-content/plugins/cryptocurrency-donation-box/admin/codestar-framework/classes/fields.class.php on line 16

Deprecated: Creation of dynamic property CSF_Field_typography::$where is deprecated in /home/mindksdy/defiprofitboost.com/wp-content/plugins/cryptocurrency-donation-box/admin/codestar-framework/classes/fields.class.php on line 17

Deprecated: Creation of dynamic property CSF_Field_typography::$parent is deprecated in /home/mindksdy/defiprofitboost.com/wp-content/plugins/cryptocurrency-donation-box/admin/codestar-framework/classes/fields.class.php on line 18

Deprecated: Creation of dynamic property CSF_Field_color::$field is deprecated in /home/mindksdy/defiprofitboost.com/wp-content/plugins/cryptocurrency-donation-box/admin/codestar-framework/classes/fields.class.php on line 14

Deprecated: Creation of dynamic property CSF_Field_color::$value is deprecated in /home/mindksdy/defiprofitboost.com/wp-content/plugins/cryptocurrency-donation-box/admin/codestar-framework/classes/fields.class.php on line 15

Deprecated: Creation of dynamic property CSF_Field_color::$unique is deprecated in /home/mindksdy/defiprofitboost.com/wp-content/plugins/cryptocurrency-donation-box/admin/codestar-framework/classes/fields.class.php on line 16

Deprecated: Creation of dynamic property CSF_Field_color::$where is deprecated in /home/mindksdy/defiprofitboost.com/wp-content/plugins/cryptocurrency-donation-box/admin/codestar-framework/classes/fields.class.php on line 17

Deprecated: Creation of dynamic property CSF_Field_color::$parent is deprecated in /home/mindksdy/defiprofitboost.com/wp-content/plugins/cryptocurrency-donation-box/admin/codestar-framework/classes/fields.class.php on line 18
BlackSuit ransomware payment recovered in takedown operation - Coin News - Latest Crypto & Blockchain News
Coin News – Latest Crypto & Blockchain News
Image default
Bitcoin BlackSuit Ransomware

BlackSuit ransomware payment recovered in takedown operation

US authorities reveal how over a million dollars’ worth of cryptocurrency assets laundered by the BlackSuit ransomware gang were seized ahead of a July takedown operation

By

  • Alex Scroxton,
    Security Editor

Published: 13 Aug 2025 16:40

Over a million dollars’ worth of cryptocurrency assets laundered by or on behalf of the notorious BlackSuit ransomware gang – previously known as Royal – were seized ahead of a multinational takedown operation in July, led by the US authorities with support from the UK’s National Crime Agency (NCA) and cyber cops from Canada, France, Germany, Ireland, Lithuania and Ukraine.

Operation Checkmate, which took place on 24 July, saw a coordinated action that took four servers and nine domains offline for good. The US Department of Justice (DoJ) has revealed that this week, a warrant for the seizure of crypto assets valued at $1.09m (£800,000) was unsealed by the US Attorney’s Offices for the Eastern District of Virginia and the District of Columbia. The seizure itself took place some months ago.

The funds in question were paid out on or around 4 April 2023 by a victim who handed over 49.31 bitcoin in exchange for the BlackSuit gang agreeing to decrypt their data. The payment was worth about $1.45m at the time. A portion of this total was repeatedly deposited and withdrawn into a virtual currency exchange account, before being frozen by the exchange in January 2024.

“Disrupting ransomware infrastructure is not only about taking down servers – it’s about dismantling the entire ecosystem that enables cyber criminals to operate with impunity,” said Michael Prado, deputy assistant director of the Cyber Crimes Center at Homeland Security Investigations (HSI), the investigative branch of the federal government Department of Homeland Security (DHS).

“This operation is the result of tireless international coordination and shows our collective resolve to hold ransomware actors accountable,” said Prado.

HSI Washington DC acting special agent in charge Christopher Heck added: “This investigation reflects the full reach of HSI’s cyber mission and our commitment to protecting victims – whether they’re small businesses, school systems, or hospitals. We will continue to target the infrastructure, finances and operators behind these ransomware groups to ensure they have nowhere left to hide.”

Deputy director Paul Foster, head of the NCA’s National Cyber Crime Unit, said: “Ransomware is the most damaging cyber crime threat globally and the BlackSuit strain has impacted victims in the UK and overseas.

“The NCA, alongside the North West Regional Organised Crime Unit worked closely with HSI and other international partners over the past year, sharing intelligence which contributed to the disruption of this criminal group.

“We continue to support UK-based victims of BlackSuit attacks and would encourage anyone who thinks they have been targeted to come forward and report it,” added Foster. “Further support and advice on protecting yourself from ransomware can be found at NCSC.gov.uk.”

This investigation reflects the full reach of HSI’s cyber mission and our commitment to protecting victims. We will continue to target the infrastructure, finances and operators behind these ransomware groups to ensure they have nowhere left to hide
Christopher Heck, Homeland Security Investigations

A prolific ransomware actor, BlackSuit was likely comprised of individuals with historic links to the Conti gang. It first surfaced in early 2022, likely acting as an affiliate of other gangs, before emerging as Royal with its own encryptor that autumn. It went on to rebrand as BlackSuit following a major attack on the City of Dallas in Texas, but it then lay quiet until last summer, when it started to ramp up the tempo of its attacks again.

During its operational life, it is thought that BlackSuit attacked almost 500 victims in the US alone and extorted over $370m in payments.

Its targeting included victims in many critical infrastructure sectors, such as government bodies, healthcare and manufacturing. As noted, one of its most noteworthy victims was the City of Dallas, which was attacked in spring 2023.

In this infamous incident, the gang was able to gain access to the city government’s systems using a stolen account, and exfiltrated over a terabyte’s worth of files over a four-week period, before executing its ransomware payload.

While BlackSuit operated a fairly standard double encryption business model, it was somewhat noteworthy in its approach to encrypting its victims’ data, using a partial encryption approach that allowed its operators to choose how much data in a file to encrypt. This tactic meant the gang could work quicker and evade detection.

The outlook is still Chaos

Notwithstanding the success of the joint operation, ransomware actors are notoriously difficult to pin down and, when cornered, have a frustrating habit of melting into the shadows and re-emerging with a new identity further down the line.

In the case of BlackSuit, the gang’s next rebrand may already be in progress. In late July, researchers at Cisco Talos published intelligence linking an emergent ransomware-as-a-service (RaaS) operation dubbed Chaos to former BlackSuit operatives.

In their assessment, the Cisco Talos team said it was likely that based on similarities in tactics, techniques and procedures (TTPs) – including encryption commands, the broad theme and structure of its ransom note, and the use of similar tools in its attacks – Chaos was “either a rebranding of the BlackSuit ransomware or operated by some of its former members”.

This article was updated at 19:35 on 13 August to incorporate a quote from the UK’s National Crime Agency.

Read more on Hackers and cybercrime prevention

  • 15 of the biggest ransomware attacks in history

    By: Mary Pratt

  • A landscape forever altered? The LockBit takedown one year on

    By: Alex Scroxton

  • 10 of the biggest ransomware attacks in 2024

    By: Arielle Waldman

  • Geopolitical strife drives increased ransomware activity

    By: Alex Scroxton

Read More

Related posts

Crypto Presales Feel Bitcoin Price Pump as 3 New Cryptos Hit BIG MONEY MILESTONES!

developer

WhatsApp provides no cryptographic management for group messages

Dogecoin Price Turns Bullish – 30% Gains In 7 Days As DOGE Pumps With These New Cryptos

developer

Leave a Comment

* By using this form you agree with the storage and handling of your data by this website.