BlackMatter Ransomware — Victims, Campaigns & Activity

Threat entity extracted from intelligence sources

Frequency
3
occurrences
First Seen
November 20, 2025
Last Seen
June 10, 2026

BlackMatter is a ransomware_group tracked across 2 threat clusters and 3 intelligence report mentions on ThreatCluster. First observed November 20, 2025; most recent activity June 10, 2026.

Overview

BlackMatter is a ransomware operation that emerged in 2021, widely suspected to be a rebrand or evolution of DarkSide-affiliated actors. It operates with a double-extortion model against Windows networks and has influenced later groups (notably BlackCat/ALPHV) through shared techniques and affiliate-style operations. It remains significant in cybersecurity as a benchmark for early extortion workflows and is referenced in defense-focused analyses and emulation exercises, such as AttackIQ's Ransom Tales, to illustrate attacker tactics against modern defenses.

Related Threat Clusters

Recent Intelligence Reports

  • New SilabRAT Trojan Hijacks Sessions to Steal Crypto — Infosecurity-Magazine · June 10, 2026
  • SilabRAT, What's Your Power? | Group — Group-Ib · June 10, 2026
  • APT41 group Tactics vs Ransomware Emulations in AttackIQ Ransom Tales — Socprime · November 20, 2025

CVSS v3.1 Breakdown