Actor Profile

🏹 blackout — Ransomware

Blackout is a ransomware group that first appeared in early 2024, initially claiming attacks against healthcare entities in Canada, France, and Germany before expanding to telecommunications, mining, and manufacturing sectors, operating a double-extortion model with a data leak site.

Classification

Ransomware

Leak-site victims

12
Ransomware.live

Associated IoCs

0
local intel

MITRE techniques

ATT&CK

Tracked

Yes
Ransomware.live

🔥 Leak-Site Victims (12)

VictimCountryPublishedDomain
yano.tokyo JP 2026-07-19T12:22:39.950334+00:00 yano.tokyo
www.miatech.net US 2026-07-19T12:22:05.640546+00:00 www.miatech.net
bluebellgroup.com GB 2026-07-19T12:21:30.932515+00:00 bluebellgroup.com
nedamaritime.gr GR 2024-12-10T05:17:11.213466+00:00 nedamaritime.gr
cdc-biodiversite.fr FR 2024-09-29T14:23:32.536590+00:00 cdc-biodiversite.fr
antaeustravel.com GR 2024-08-22T15:10:01.336221+00:00 antaeustravel.com
luzan5.com 2024-07-14T11:32:51.193470+00:00 luzan5.com
badel1862.hr HR 2024-07-03T15:12:36.069531+00:00 badel1862.hr
mcmtelecom.com MX 2024-05-29T14:48:19.870928+00:00 mcmtelecom.com
ht-hospitaltechnik.de DE 2024-04-18T13:33:35.020896+00:00 ht-hospitaltechnik.de
metal7.com CA 2024-02-26T22:34:22.675676+00:00 metal7.com
ch-armentieres.fr FR 2024-02-26T22:35:02.607800+00:00 ch-armentieres.fr

Source: Ransomware.live leak-site monitoring (cached, offline-safe).

📁 Case Management

+ New case from this

🏹 Add to case

Attach blackout (Actor / APT) and pull all linked entities:

🧭 Intelligence disciplines

CYBINT →OSINT →HUMINT →GEOINT →
Live group profile & victims via Ransomware.live; ATT&CK technique hints are a static reference for well-known groups. All network calls cached & offline-safe.
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php