BlackMatter is a ransomware_group tracked across 2 threat clusters and 3 intelligence report mentions on ThreatCluster. First observed November 20, 2025; most recent activity June 10, 2026.
BlackMatter is a ransomware operation that emerged in 2021, widely suspected to be a rebrand or evolution of DarkSide-affiliated actors. It operates with a double-extortion model against Windows networks and has influenced later groups (notably BlackCat/ALPHV) through shared techniques and affiliate-style operations. It remains significant in cybersecurity as a benchmark for early extortion workflows and is referenced in defense-focused analyses and emulation exercises, such as AttackIQ's Ransom Tales, to illustrate attacker tactics against modern defenses.
The SilabRAT, a Remote Access Trojan (RAT), has emerged on dark web forums as a Malware-as-a-Service (MaaS) offering since late 2025, priced at $5,000 per month. Developed by the Russian-speaking actor 'o1oo1', it is…
The article discusses the fifth volume of AttackIQ’s Ransom Tales series, which simulates the tactics of ransomware families REvil, DarkSide, and BlackMatter. These emulations are designed to help organizations validate…