Threat Intelligence Tarot
pentacles · 4
Criminal (Russian-speaking, DarkSide successor)
G0139★★★★★
risk 4/5
✦ The Rebrand ✦
BlackMatter
DarkSide rebranded · ALPHV precursor
AgricultureFood supply chainManufacturingCritical infrastructure
Active ~2021 · Ransomware operations post-Colonial, Critical infrastructure targeting (selective), RaaS affiliate model
DarkSide died after Colonial Pipeline. BlackMatter was born two months later. It promised not to hit hospitals or pipelines - then hit grain cooperatives during harvest season. The Rebrand learned the wrong lessons: it thought the problem was the target, not the crime. It lasted three months.
Tactics & Techniques
RCN
RDV
INI
EXC
PRS
PRV
EVA
CRD
DSC
LAT
COL
C2
EXF
IMP
Notable Operations
- ◆Iowa-based grain cooperative NEW Cooperative ransomware attack (2021)
- ◆Crystal Valley Cooperative attack during harvest season
- ◆US food supply chain disruption during critical agricultural period
- ◆Shut down within 3 months under law enforcement pressure
Defenses
- ▸Agricultural sector ICS/OT security and network segmentationNIST SP 800-82 ↗
- ▸Backup and recovery testing for operational technology systemsCIS Control 11 ↗
- ▸Ransomware incident response planning for supply chain disruptionNIST CSF: RS.RP ↗
- ▸AG-ISAC threat intelligence sharing for food and agriculture sectorNIST CSF: ID.RA ↗
Reversed: Their Weakness
BlackMatter's rapid shutdown demonstrates the fragility of RaaS operations under sustained law enforcement pressure - the Colonial Pipeline aftermath created an environment where even renamed, restructured ransomware groups could not operate without existential risk from multiple international agencies.
Share this adversary profile
swipe to browse
Related Adversaries
Data sourced from MITRE ATT&CK. For educational purposes.