Blackout 家族详情

Blackout

高活跃

暂无信息

首次发现 :
勒索信 : BLACKOUT_NOTE.pdf
算法 : AES-ECB
扩展名 : .auZW7lSsp;blacked

情报摘要:

别名 :
IOC数量 :
5
受害记录 :
0
ATT&CK战术 :
21

概览

暂无信息

加密特征

暂无加密特征数据。

勒索信

勒索信文件 : BLACKOUT_NOTE.pdf

BLACKOUT_NOTE Dear ***, unfortunately, you’re out of luck - your local network is encrypted, and confidential information has been uploaded to external servers. Please read the text below carefully and consider all possible scenarios. If you are a technical specialist without the necessary credentials, please provide this file unmodified to company management. (!) Do not convey the basic essence in words, this will interfere with the understanding of the situation and can decide the fate of the entire company. What Happened You have fallen victim to an attack by an organized hacker group. We spent a significant amount of time inside your local network - reading your emails, accessing internal files, and compromising multiple workstations and servers. This was not an automated attack. Encryption We have encrypted the majority of your critical infrastructure and destroyed all accessible backups. Without our assistance, you will not be able to recover the encrypted files - this will severely disrupt your business operations. About decrypting the files Encryption Details Your files have been encrypted using RSA-2048 asymmetric encryption. Without the private key which is exclusively in our possession and was never stored on your network - recovery is impossible. Beware of Scammers Many fraudulent actors claim to offer decryption services. Do not waste your time or money - they cannot help you. Proof of Decryption When you contact us, we will decrypt several sample files that you provide us for free, proving that: 1. Decryption is possible. 2. We hold the only valid key. You can provide absolutely any encrypted file, we could not download your entire network, so we cannot take it from our copies. ANY INTERACTIONS WITH THE FILES MAY CAUSE THEM TO BECOME CORRUPTED, WE CAN'T HELP YOU WITH THEM AFTER THAT, MAKE BACKUPS IF YOU WANT TO EXPERIMENT WITH THEM. For *** We were on your network for a couple of months, it was extremely difficult to move deeper, you have good password management, especially for Linux hosts, but everything became easier after capturing a couple of jumpservers. We are sure that most of the backups were deleted, ordinary workstations of which a couple of thousand were not backed up in any way, most of the tape media were damaged and recovery from them is impossible. Not all, but a large proportion of Linux hosts are also in poor condition. In general, corporate processes are frozen for an indefinite period, which is why you are already losing a lot of money. Stolen sensitive data Second Critical Point: We have copied significant amounts of your sensitive data to our servers and will publish everything unless we reach an agreement. The immediate consequences include: Severe reputational damage Operational risks from leaked source code containing security vulnerabilities Exposure of customer databases (including names, email addresses, and passwords) Vulnerability to follow-up attacks as other threat actors exploit the leaked data For *** You have an incredibly huge network, of course we couldn’t copy even a couple percent of the files from it, but we tried to take the most valuable. oa.***.com Source files, deployment .war files and of course the dump of the oracle database from ***, it is large, some garbage tables were truncated. ***File Encryption System It was critical to take this with you otherwise many of the files would be unusable. We took the server and client sources (from the workstation of one of the admins, it seems ***, although he is generally evil, we never penetrated ***), installers and of course a database dump with cryptographic keys for decryption (***). We have not done this, but we are confident that with this data posible decrypt any of your CDG files. *** peoplesoft Here was the data of all your employees, more than *** records, their addresses, numbers, personal emails, and many had identification documents. There is also a lot of interesting information about the company’s assets. This system is some kind of IT hell, but we found the complete database - ***. *** dump, also without a couple of garbage tables. *** customer management system *** database dump, .war application file, part of the attached files. There are data on contracts, information about other companies, etc. In theory, your competitors might like it. pan.***.com We did not have full admin access to this system, although we tried very hard, the admin definitely received a couple of notifications on his phone. However, we were able to gain full access to many important shares. We copied *** files from DepartmentShare, office documents, photos, spreadsheets, documentation, etc. Our Offer We offer the following: Full decryption tool - Complete recovery of all your encrypted files Complete data deletion - Permanent removal of all stolen files from our servers, with guarantee that no copies were shared with third parties Non-attack guarantee - We will not target your organization in the future Optional security report - Detailed breakdown of our infiltration method and security recommendations to prevent future breaches Price: *** This is *** of your annual revenue, you will definitely lose more without dialogue with us. Possible scenarios and risks The possible scenarios are globally 2: You agree to our deal. We understand that there is a risk that we will not fulfill our obligations after payment. We can take a logical approach to this issue. We offer you to decrypt some files for free, so we have a decryptor, to pass it to you is just to send an exe file, even easier than decrypting your test files, we have no reason not to do it after payment, on the contrary otherwise we will lose reputation, not only ours, but the whole sphere, you can search for such cases almost never happened. Also we can not delete your files, it also has little sense, we want from you hundreds of times more money than you can get from these files. We may try to attack you again, but we hope that you will make a conclusion from this situation and will better protect your network and even if not, most likely you just will not pay a second time, why should we waste our efforts. You're not accepting our deal. You can contact cybercriminalization companies, your government services, ask for a tax deferral, you may be able to protect your network, you may be able to put some EDR for a lot of money, but the underlying problem will not go away, your files will remain encrypted, and important information will be publicly available. There is also the risk of repeated attacks, we may realize that you don't want to cooperate and slam the door very loudly. How to contact us We have our own portal on the Tor network. Visit our site on the Tor network: You will need to download the Tor Browser. *** Our portal URL: *** Then you can log into your personal account, there will be more information and chat with support. Your COMPANY_ID for login: *** If you have problems with Tor, you can write to us directly in TOX Chat: *** ToxID: *** In tox, the dialog connection works directly without servers, try to keep the application always running. We are unlikely to respond instantly, but we will respond within 24 hours, stay tuned. Deadlines If you enter into dialogue, we will freeze all timers for the duration of the negotiations. *** We will make a post about your company (without the ability to download your files), the specialized media will notice this and you will have additional problems. It would be best to write before this time if you want to cooperate. In your case, things get complicated by the fact that you have stocks trading on the American exchange (***), and the publication of the news will definitely affect them. *** We will publish all your data. Further negotiations are impossible. We are waiting for dialogue.

技术细节

Blackout 勒索家族目前缺乏可公开核验的技术细节,尚无稳定披露的样本语言、文件扩展名、勒索信命名规则、互斥体、配置结构或 C2 协议。基于现有公开信息,不能确认其是否具备独立加密器、泄露站点、Linux/ESXi 版本或域内横向移动组件。

可确认程度较低的关键技术项如下:

  • 代码语言:暂无公开信息,未见权威报告确认其由 C/C++、Go、Rust、.NET 或脚本语言编写。
  • 文件特征:暂无公开信息,未确认加密后缀、勒索信文件名、图标、PDB 路径、编译时间戳或打包器特征。
  • 互斥体:暂无公开信息,未见稳定 mutex、命名管道或单实例运行标识披露。
  • 持久化:暂无公开信息,不能确认是否使用计划任务、服务、Run 键、WMI 事件订阅等方式维持访问。
  • 防御规避:暂无公开信息,未确认是否终止安全软件、清除日志、禁用 Defender、绕过 UAC 或使用合法签名工具。
  • C2 通信:暂无公开信息,未确认是否存在硬编码 C2、Tor 通信、HTTP(S) Beacon、代理隧道或仅离线加密执行。

因此,对 Blackout 的技术分析应以样本静态/动态验证为准,重点关注进程创建链、文件重命名行为、卷影副本操作、凭据访问工具落地、域控连接记录以及异常大规模文件写入事件。

威胁指标

ip 地址

恶意IP地址

45.67.228.215

来源 : Solar296项目捕获
首次录入 : 2026-03-04
最后更新 : 2026-09-01

ip地址

恶意IP地址

178.16.52.38

来源 : Solar296项目捕获
首次录入 : 2026-03-04
最后更新 : 2026-09-01

MD5

恶意软件样本

03f683737378c9b167f91989bafcf2e9

来源 : Solar296项目捕获
首次录入 : 2026-03-04
最后更新 : 2026-09-01

sha256

恶意软件样本

8d234417d1d81713eba8edc1c2a4fa45eca3143cb5917ac395c0276aae146f97

来源 : Solar296项目捕获
首次录入 : 2026-03-04
最后更新 : 2026-09-01

sha256

恶意软件样本

579be89a6f4ce6e7a9ed01524ca473363e2b6a0b1253294654f253ea737c9341

来源 : Solar296项目捕获
首次录入 : 2026-03-04
最后更新 : 2026-09-01

受害者信息

暂无受害者记录。

MITRE ATT&CK

公开威胁情报中,Blackout 的完整攻击链暂无足够可验证披露,以下仅给出分析时应映射和核验的 ATT&CK 方向,不能视为该家族已确认 TTP。

  • 初始访问:暂无公开信息。需重点核验是否涉及钓鱼邮件 T1566、外部远程服务暴露 T1133、有效账号登录 T1078、漏洞利用公开应用 T1190,但目前不能归因到 Blackout。
  • 执行:暂无公开信息。样本分析时应关注命令行解释器 T1059、PowerShell T1059.001、Windows 服务执行 T1569.002、计划任务执行 T1053.005 等行为。
  • 持久化:暂无公开信息。需核验是否创建服务 T1543.003、注册表 Run 键 T1060/T1547.001、计划任务 T1053.005 或使用远程管理工具维持访问。
  • 权限提升与横向移动:暂无公开信息。应排查凭据转储 T1003、SMB/Windows Admin Shares T1021.002、RDP T1021.001、PsExec 类工具 T1570 等迹象。
  • 防御规避:暂无公开信息。重点关注禁用安全工具 T1562.001、删除日志 T1070、混淆文件或信息 T1027、合法工具滥用 T1218
  • 加密勒索:若确认存在文件加密行为,应映射到数据加密影响 T1486;若删除卷影副本或备份,应映射到抑制系统恢复 T1490;若存在数据窃取和双重勒索,应核验数据外传 T1041 或替代通道外传 T1105。目前这些能力均暂无公开信息确认。

处置建议

  1. 优先核查远程接入(VPN/RDP)暴露面与弱口令,启用 MFA。

  2. 验证备份的离线可用性,确保备份不可被加密或删除。

  3. 及时清理高权限账号与可疑会话,排查 AD 域控异常。

  4. 结合 IOC 对历史日志、终端文件与网络连接进行回溯。

  5. 隔离疑似受影响资产,保留勒索信与样本供分析。

常见行业

制造业
科技
工业组织

常见入口

  • VPN 暴露
  • RDP 弱口令
  • 钓鱼邮件
  • 公开服务
  • 供应链入口
  • 远程运维

操作协助

把热线、演示和资料入口拆开,让应急处置、产品评估和补充阅读各自清晰

电话咨询

出现加密、停摆或勒索提示时,优先直接联系应急响应团队。

400-613-6816

预约演练

如果你在评估产品、后台和家族库能力,可以先预约一个简短演示。

预约30分钟

查看资料

把文章、工具和方案入口集中到一起,方便团队继续同步研判。

进入资料中心

5000+

服务客户

99.8%

平均恢复率

<5min

首次响应

50+

安全专家