BlackSuit infrastructure takedown
weg7sdx54bevnvulapqu6bpzwztryeflq3s23tegbmnhkbpqz637f2yd.onion
ransomware
Summary
The BlackSuit onion address was archived with an Operation Checkmate seizure notice dated 24 July 2025. The U.S. Department of Justice later confirmed that coordinated actions on that date took down four servers and nine domains.
Before and after
BEFORE
No independently replayable pre-seizure capture of this exact onion address was found in the public web archives reviewed.
AFTER
Snapshot file unavailable. The metadata survived. Small victories.
Status history
- ONLINE → SEIZED
Coordinated actions took down BlackSuit servers and domains, and a seizure notice was archived for this address.
Record details
What happened?
The BlackSuit onion address was archived with an Operation Checkmate seizure notice dated 24 July 2025. The U.S. Department of Justice later confirmed that coordinated actions on that date took down four servers and nine domains.
Related infrastructure
No replacement domain or mirror has been confirmed.
Related ransomware research
Extortion Wiki documents the actor, negotiations, ransom notes, victims, and related ransomware activity.
Related malware research
vx-underground provides malware-family samples and technical research. These links provide family context and do not serve as evidence for the takedown documented above.
Sources
-
Justice Department Announces Coordinated Disruption Actions Against BlackSuit (Royal) Ransomware Operations
U.S. Department of Justice
-
BlackSuit / Operation Checkmate seizure banner
Extortion Wiki
Record quality
Found an error?
Send the record URL, the incorrect claim, and a source supporting the correction. “My friend said so” remains unsupported even when your friend types confidently.