Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Biohacking Implants: When Human Optimization Becomes Too Risky

    NTT Data deepens Middle East cloud push with acquisition of UAE-based Zero&One

    UAE’s TII challenges big tech dominance with open source Falcon AI models

    Facebook X (Twitter) Instagram
    • Artificial Intelligence
    • Business Technology
    • Cryptocurrency
    • Gadgets
    • Gaming
    • Health
    • Software and Apps
    • Technology
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Tech AI Verse
    • Home
    • Artificial Intelligence

      Read the extended transcript: President Donald Trump interviewed by ‘NBC Nightly News’ anchor Tom Llamas

      February 6, 2026

      Stocks and bitcoin sink as investors dump software company shares

      February 4, 2026

      AI, crypto and Trump super PACs stash millions to spend on the midterms

      February 2, 2026

      To avoid accusations of AI cheating, college students are turning to AI

      January 29, 2026

      ChatGPT can embrace authoritarian ideas after just one prompt, researchers say

      January 24, 2026
    • Business

      New VoidLink malware framework targets Linux cloud servers

      January 14, 2026

      Nvidia Rubin’s rack-scale encryption signals a turning point for enterprise AI security

      January 13, 2026

      How KPMG is redefining the future of SAP consulting on a global scale

      January 10, 2026

      Top 10 cloud computing stories of 2025

      December 22, 2025

      Saudia Arabia’s STC commits to five-year network upgrade programme with Ericsson

      December 18, 2025
    • Crypto

      Bernstein Discusses Bitcoin’s Weakest Bear Market Yet – “Nothing Broke”

      February 9, 2026

      Ethereum Price Hits Breakdown Target — But Is a Bigger Drop to $1,000 Coming?

      February 9, 2026

      Damex Secures MiCA CASP Licence, Establishing Its Position as a Tier-1 Digital Asset Institution in Europe

      February 9, 2026

      Bitget and BlockSec Introduce the UEX Security Standard, Setting a New Benchmark for Universal Exchanges

      February 9, 2026

      3 Meme Coins To Watch In The Second Week Of February 2026

      February 9, 2026
    • Technology

      Biohacking Implants: When Human Optimization Becomes Too Risky

      February 9, 2026

      NTT Data deepens Middle East cloud push with acquisition of UAE-based Zero&One

      February 9, 2026

      UAE’s TII challenges big tech dominance with open source Falcon AI models

      February 9, 2026

      US bid for Dutch ID infrastructure raises sovereignty concerns

      February 9, 2026

      ExpressVPN two-year plans are up to 81 percent off right now

      February 9, 2026
    • Others
      • Gadgets
      • Gaming
      • Health
      • Software and Apps
    Check BMI
    Tech AI Verse
    You are at:Home»Technology»BlackSuit ransomware payment recovered in takedown operation
    Technology

    BlackSuit ransomware payment recovered in takedown operation

    TechAiVerseBy TechAiVerseAugust 13, 2025No Comments5 Mins Read3 Views
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    BlackSuit ransomware payment recovered in takedown operation
    Share
    Facebook Twitter LinkedIn Pinterest WhatsApp Email

    BlackSuit ransomware payment recovered in takedown operation

    US authorities reveal how over a million dollars’ worth of cryptocurrency assets laundered by the BlackSuit ransomware gang were seized ahead of a July takedown operation

    By

    • Alex Scroxton,
      Security Editor

    Published: 13 Aug 2025 16:40

    Over a million dollars’ worth of cryptocurrency assets laundered by or on behalf of the notorious BlackSuit ransomware gang – previously known as Royal – were seized ahead of a multinational takedown operation in July, led by the US authorities with support from the UK’s National Crime Agency (NCA) and cyber cops from Canada, France, Germany, Ireland, Lithuania and Ukraine.

    Operation Checkmate, which took place on 24 July, saw a coordinated action that took four servers and nine domains offline for good. The US Department of Justice (DoJ) has revealed that this week, a warrant for the seizure of crypto assets valued at $1.09m (£800,000) was unsealed by the US Attorney’s Offices for the Eastern District of Virginia and the District of Columbia. The seizure itself took place some months ago.

    The funds in question were paid out on or around 4 April 2023 by a victim who handed over 49.31 bitcoin in exchange for the BlackSuit gang agreeing to decrypt their data. The payment was worth about $1.45m at the time. A portion of this total was repeatedly deposited and withdrawn into a virtual currency exchange account, before being frozen by the exchange in January 2024.

    “Disrupting ransomware infrastructure is not only about taking down servers – it’s about dismantling the entire ecosystem that enables cyber criminals to operate with impunity,” said Michael Prado, deputy assistant director of the Cyber Crimes Center at Homeland Security Investigations (HSI), the investigative branch of the federal government Department of Homeland Security (DHS).

    “This operation is the result of tireless international coordination and shows our collective resolve to hold ransomware actors accountable,” said Prado.

    HSI Washington DC acting special agent in charge Christopher Heck added: “This investigation reflects the full reach of HSI’s cyber mission and our commitment to protecting victims – whether they’re small businesses, school systems, or hospitals. We will continue to target the infrastructure, finances and operators behind these ransomware groups to ensure they have nowhere left to hide.”

    Deputy director Paul Foster, head of the NCA’s National Cyber Crime Unit, said: “Ransomware is the most damaging cyber crime threat globally and the BlackSuit strain has impacted victims in the UK and overseas.

    “The NCA, alongside the North West Regional Organised Crime Unit worked closely with HSI and other international partners over the past year, sharing intelligence which contributed to the disruption of this criminal group.

    “We continue to support UK-based victims of BlackSuit attacks and would encourage anyone who thinks they have been targeted to come forward and report it,” added Foster. “Further support and advice on protecting yourself from ransomware can be found at NCSC.gov.uk.”

    This investigation reflects the full reach of HSI’s cyber mission and our commitment to protecting victims. We will continue to target the infrastructure, finances and operators behind these ransomware groups to ensure they have nowhere left to hide
    Christopher Heck, Homeland Security Investigations

    A prolific ransomware actor, BlackSuit was likely comprised of individuals with historic links to the Conti gang. It first surfaced in early 2022, likely acting as an affiliate of other gangs, before emerging as Royal with its own encryptor that autumn. It went on to rebrand as BlackSuit following a major attack on the City of Dallas in Texas, but it then lay quiet until last summer, when it started to ramp up the tempo of its attacks again.

    During its operational life, it is thought that BlackSuit attacked almost 500 victims in the US alone and extorted over $370m in payments.

    Its targeting included victims in many critical infrastructure sectors, such as government bodies, healthcare and manufacturing. As noted, one of its most noteworthy victims was the City of Dallas, which was attacked in spring 2023.

    In this infamous incident, the gang was able to gain access to the city government’s systems using a stolen account, and exfiltrated over a terabyte’s worth of files over a four-week period, before executing its ransomware payload.

    While BlackSuit operated a fairly standard double encryption business model, it was somewhat noteworthy in its approach to encrypting its victims’ data, using a partial encryption approach that allowed its operators to choose how much data in a file to encrypt. This tactic meant the gang could work quicker and evade detection.

    The outlook is still Chaos

    Notwithstanding the success of the joint operation, ransomware actors are notoriously difficult to pin down and, when cornered, have a frustrating habit of melting into the shadows and re-emerging with a new identity further down the line.

    In the case of BlackSuit, the gang’s next rebrand may already be in progress. In late July, researchers at Cisco Talos published intelligence linking an emergent ransomware-as-a-service (RaaS) operation dubbed Chaos to former BlackSuit operatives.

    In their assessment, the Cisco Talos team said it was likely that based on similarities in tactics, techniques and procedures (TTPs) – including encryption commands, the broad theme and structure of its ransom note, and the use of similar tools in its attacks – Chaos was “either a rebranding of the BlackSuit ransomware or operated by some of its former members”.

    This article was updated at 19:35 on 13 August to incorporate a quote from the UK’s National Crime Agency.

    Read more on Hackers and cybercrime prevention


    • 15 of the biggest ransomware attacks in history

      By: Mary Pratt


    • A landscape forever altered? The LockBit takedown one year on

      By: Alex Scroxton


    • 10 of the biggest ransomware attacks in 2024

      By: Arielle Waldman


    • Geopolitical strife drives increased ransomware activity

      By: Alex Scroxton

    Share. Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Telegram Email
    Previous ArticleSantander will make AI training mandatory for all staff in 2026
    Next Article Abandoned Spotify Car Thing revived by free firmware that restores original functionality and then some
    TechAiVerse
    • Website

    Jonathan is a tech enthusiast and the mind behind Tech AI Verse. With a passion for artificial intelligence, consumer tech, and emerging innovations, he deliver clear, insightful content to keep readers informed. From cutting-edge gadgets to AI advancements and cryptocurrency trends, Jonathan breaks down complex topics to make technology accessible to all.

    Related Posts

    Biohacking Implants: When Human Optimization Becomes Too Risky

    February 9, 2026

    NTT Data deepens Middle East cloud push with acquisition of UAE-based Zero&One

    February 9, 2026

    UAE’s TII challenges big tech dominance with open source Falcon AI models

    February 9, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Ping, You’ve Got Whale: AI detection system alerts ships of whales in their path

    April 22, 2025660 Views

    Lumo vs. Duck AI: Which AI is Better for Your Privacy?

    July 31, 2025249 Views

    6.7 Cummins Lifter Failure: What Years Are Affected (And Possible Fixes)

    April 14, 2025148 Views

    6 Best MagSafe Phone Grips (2025), Tested and Reviewed

    April 6, 2025111 Views
    Don't Miss
    Technology February 9, 2026

    Biohacking Implants: When Human Optimization Becomes Too Risky

    Biohacking Implants: When Human Optimization Becomes Too Risky Image source: recovery.com Key takeaways: Biohacking has…

    NTT Data deepens Middle East cloud push with acquisition of UAE-based Zero&One

    UAE’s TII challenges big tech dominance with open source Falcon AI models

    US bid for Dutch ID infrastructure raises sovereignty concerns

    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    About Us
    About Us

    Welcome to Tech AI Verse, your go-to destination for everything technology! We bring you the latest news, trends, and insights from the ever-evolving world of tech. Our coverage spans across global technology industry updates, artificial intelligence advancements, machine learning ethics, and automation innovations. Stay connected with us as we explore the limitless possibilities of technology!

    Facebook X (Twitter) Pinterest YouTube WhatsApp
    Our Picks

    Biohacking Implants: When Human Optimization Becomes Too Risky

    February 9, 20264 Views

    NTT Data deepens Middle East cloud push with acquisition of UAE-based Zero&One

    February 9, 20264 Views

    UAE’s TII challenges big tech dominance with open source Falcon AI models

    February 9, 20263 Views
    Most Popular

    7 Best Kids Bikes (2025): Mountain, Balance, Pedal, Coaster

    March 13, 20250 Views

    VTOMAN FlashSpeed 1500: Plenty Of Power For All Your Gear

    March 13, 20250 Views

    This new Roomba finally solves the big problem I have with robot vacuums

    March 13, 20250 Views
    © 2026 TechAiVerse. Designed by Divya Tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms & Conditions

    Type above and press Enter to search. Press Esc to cancel.