Blacktail
0 incidentes
0 paises
0 sectores
apt CN Ultimo: -
Blacktail, also known as Buhti, is a ransomware operation that emerged in February 2023, distinguished by its rapid exploitation of newly disclosed vulnerabilities and its reliance on repurposed leaked ransomware code. While the group does not develop its own ransomware strains, it notably utilizes modified variants of the leaked LockBit 3.0 ransomware for Windows systems and Babuk ransomware for Linux and ESXi environments. A core characteristic that sets Blacktail apart is its development and deployment of a custom, Golang-based information stealer for data exfiltration, which complements its double extortion strategy. Symantec tracks this group under the name Blacktail, whereas other security researchers and the group's ransomware payload often refer to it as Buhti.
Sectores objetivo (OSINT)
National Security&International AffairsBanking