BLACKCAT RANSOMWARE
Based on our profiling analysis, the site is largely operated by east-European individuals based on sentence structure. The communiction site also offers an intermediary access (private access to negotiators). Primary motivation is based on monetary gain and the group offers access to their encryption software (aka Malware aka Ransomware) on a paid and commission based subscription model (RaaS). The group has no political interests but CYPFER has noticed that no attacks against Russian/Ukrainian or other East-European attacks were evident or supported by the group. NOTE: Whenever a ransomware group offers “private access” to negotiators, ensure that you request full transcript of any out of band communications. Transparency throughout the negotiation process is critical to keep victims informed of any communication protocols, decisions and information that might be critical not only to the negotiation process itself but also to the investigation into the incident and to ensu...