blacksnake

First seen
2022-08-01 00:00:00
Malware type
ransomware
Family
Malware family
Last IoC activity
2026-04-29 07:00:33
Profile updated
2026-07-07 13:58:36

Context

BlackSnake is a Ransomware-as-a-Service (RaaS) operation that first appeared in August 2022, when its operators began recruiting affiliates on underground forums with an unusually low revenue share of 15%. It primarily targets home users rather than large enterprises and does not maintain a public leak site. Built on the Chaos ransomware code base, it features both file encryption and a cryptocurrency clipper module to steal funds from victims. The ransomware is developed in .NET and includes safeguards to avoid execution in Turkish or Azerbaijani environments, suggesting geographic targeting preferences. Infections result in encrypted files and ransom notes instructing victims to make contact via email for payment negotiations. The group’s operational scale and visibility remain limited compared to major RaaS families.

Reports & references

  • ransomlook.io — Blacksnake (report)
  • netskope.com — Netskope Threat Coverage Blacksnake Ransomware (report)
  • Broadcom/Symantec — Blacksnake Ransomware Another Chaos Variant (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Blacksnake (report)
  • blog.cyble.com — Blacksnake Ransomware Emerges From Chaos Ransomwares Shadow (report)

External references