BlackMatter ransomware ceases operation due to police pressure

Representational image of a cybercriminal
(Image credit: Pixabay)

The BlackMatter ransomware gang has reportedly decided to call it quits, citing recent operations against it from the law enforcement agencies.

The news comes courtesy of a screenshot of a message allegedly shared by BlackMatter operatives with their “clients”. The message, posted on November 1, and originally shared by cybersecurity research group VX-Underground, suggested the group will shutdown within 48 hours.

"Due to certain unsolvable circumstances associated with pressure from the authorities (part of the team is no longer available, after the latest news) - project is closed,” reads a rough English translation of the Russian post.

TechRadar needs you!

We're looking at how our readers use VPNs with streaming sites like Netflix so we can improve our content and offer better advice. This survey won't take more than 60 seconds of your time, and we'd hugely appreciate if you'd share your experiences with us.

>> Click here to start the survey in a new window <<

Like most notorious ransomware gangs, BlackMatter operates through a ransomware-as-a-service (RaaS) model, and hosts a website to engage and communicate with its affiliates, which is where the message was posted.

Rise like a phoenix

Even if the post is legitimate, the message doesn’t mean that the ransomware gang will stop extorting victims. In fact, in the post itself, BlackMatter asks affiliates to get in touch in case they need the decryptor for BlackMatter’s ransomware, hinting that it wouldn’t stop its affiliates from taking more victims.

Furthermore, reporting on the development, BleepingComputer argues that although the group claimed that it will close its door within 48 hours, the time has come and gone but the gang’s Tor payment portal and data leak website remain operational.

Realistically speaking, such shutdowns are a mere hogwash, and a prelude to the ransomware gang re-emerging under a new name, says BleepingComputer

In fact, BlackMatter itself is a rebrand of the DarkSide gang, which shut down after it attracted a lot of heat from the law enforcement following the attack on Colonial Pipeline

Don't rely on such shutdowns to save yourself from ransomware attacks. Rather use one of these best firewall apps and services to shield your networks, and ensure your computers are running these best endpoint protection tools to add another layer of defense against cyber-attacks.

Mayank Sharma

With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’s TechRadar Pro’s expert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.

Read more
A laptop with a red screen with a white skull on it with the message: &quot;RANSOMWARE. All your files are encrypted.&quot;
Less than half of ransomware incidents end in payment - but you should still be on your guard
Ransomware
8base ransomware site taken down in global police operation
A laptop with a red screen with a white skull on it with the message: &quot;RANSOMWARE. All your files are encrypted.&quot;
More reports claim 2024 was the worst year for ransomware attacks yet
Cryptocurrencies
Ransomware’s favorite Russian crypto exchange seized by law enforcement
Hands typing on a keyboard surrounded by security icons
35 years on: The history and evolution of ransomware
Representational image of a cybercriminal
Should ransomware payments be illegal?
Latest in Security
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
An abstract image of digital security.
Fake file converters are stealing info, pushing ransomware, FBI warns
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Coinbase targeted after recent Github attacks
hacker.jpeg
Key trusted Microsoft platform exploited to enable malware, experts warn
IBM office logo
IBM to provide platform for flagship cyber skills programme for girls
Latest in News
Zendesk Relate 2025
Zendesk Relate 2025 - everything you need to know as the event unfolds
Disney Plus logo with popcorn
You can finally tell Disney+ to stop bugging you about that terrible Marvel show you regret starting
Google Gemini AI
Gemini can now see your screen and judge your tabs
Girl wearing Meta Quest 3 headset interacting with a jungle playset
Latest Meta Quest 3 software beta teases a major design overhaul and VR screen sharing – and I need these updates now
Philips Hue
Philips Hue might be working on a video doorbell, and according to a new report, we just got our first look at it
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand