{"id":52174,"date":"2023-06-02T15:48:52","date_gmt":"2023-06-02T15:48:52","guid":{"rendered":"https:\/\/packetstormsecurity.com\/news\/view\/34686\/BlackCat-Updates-Tradecraft-With-Stealth-And-Speed.html"},"modified":"2023-06-02T15:48:52","modified_gmt":"2023-06-02T15:48:52","slug":"blackcat-updates-tradecraft-with-stealth-and-speed","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/blackcat-updates-tradecraft-with-stealth-and-speed\/","title":{"rendered":"BlackCat Updates Tradecraft With Stealth And Speed"},"content":{"rendered":"<div><img decoding=\"async\" src=\"https:\/\/files.scmagazine.com\/wp-content\/uploads\/2023\/06\/cat-black-panther.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<p>Ransomware group BlackCat (also known as ALPHV) has risen to prominence over the past 18 months and new research details how a retooling of its tradecraft earlier this year made it an even more powerful threat.<\/p>\n<p>\u201cBlackCat has become known as a highly formidable and innovative ransomware operation since its debut in November 2021,\u201d researchers from IBM Security X-Force said in an <a rel=\"noreferrer noopener\" href=\"https:\/\/securityintelligence.com\/posts\/blackcat-ransomware-levels-up-stealth-speed-exfiltration\/\" target=\"_blank\">analysis of the group and its evolving malware<\/a> posted Tuesday.<\/p>\n<p>\u201cBlackCat has consistently been listed among the top 10 most active ransomware groups by multiple research entities and was linked in an <a href=\"https:\/\/www.scmagazine.com\/news\/ransomware\/fbi-seeks-information-on-alphv-ransomware-group-aka-blackcat\" target=\"_blank\" rel=\"noreferrer noopener\">April 2022 FBI advisory<\/a> to now-defunct BlackMatter\/DarkSide ransomware.\u201d<\/p>\n<h2>Despicable track record<\/h2>\n<p>The Russia-based group and its affiliates have attempted extortions around the world and across multiple industries, sometimes putting pressure on victims by publishing sensitive stolen data including financial and medical information.<\/p>\n<p>In March in <a href=\"https:\/\/www.scmagazine.com\/analysis\/ransomware\/ransomware-groups-take-extortion-tactics-to-new-heights-in-attacks-against-hospitals-schools\" target=\"_blank\" rel=\"noreferrer noopener\">released photos<\/a> of topless female breast cancer patients at the Lehigh Valley Health Network after the organization refused to pay a $1.5 million ransom following <a href=\"https:\/\/www.scmagazine.com\/news\/ransomware\/patient-data-stolen-centrastate-cyberattack-impacting-617k\" target=\"_blank\" rel=\"noreferrer noopener\">an attack in February<\/a>.<\/p>\n<p>Since then, BlackCat victims have included <a rel=\"noreferrer noopener\" href=\"https:\/\/www.scmagazine.com\/news\/breach\/data-storage-firm-western-digital-confirms-cyberattack-disrupted-operations\" target=\"_blank\">Western <\/a><a href=\"https:\/\/www.scmagazine.com\/news\/breach\/data-storage-firm-western-digital-confirms-cyberattack-disrupted-operations\">Digital<\/a>, <a rel=\"noreferrer noopener\" href=\"https:\/\/www.scmagazine.com\/brief\/ransomware\/ransomware-attack-confirmed-by-sun-pharmaceuticals\" target=\"_blank\">Sun Pharmaceuticals<\/a>, <a rel=\"noreferrer noopener\" href=\"https:\/\/www.scmagazine.com\/brief\/ransomware\/constellation-software-confirms-alphv-ransomware-claimed-attack\" target=\"_blank\">Constellation Software<\/a>.<\/p>\n<p>\u201cRansomware groups like BlackCat that are able to shift their tooling and tradecraft to make their operations faster and stealthier have a better chance of extending their lifespan,\u201d IBM Security X-Force said in its post.<\/p>\n<p>SC Media reported in May a Trend Micro finding that BlackCat was <a rel=\"noreferrer noopener\" href=\"https:\/\/www.scmagazine.com\/news\/ransomware\/blackcat-ransomware-takes-control-of-protected-computers-via-new-kernel-driver\" target=\"_blank\">deploying a new kernel driver<\/a> that leveraged a separate user client executable to control, pause and kill various processes on target endpoints of security agents deployed on protected computers.<\/p>\n<h2>Updated tradecraft<\/h2>\n<p>That appears to be one of the attributes of a new version of its ransomware, which it calls Sphynx, that the group promoted to its affiliates in February. VX-Underground <a href=\"https:\/\/twitter.com\/vxunderground\/status\/1649094229413761030\" target=\"_blank\" rel=\"noreferrer noopener\">posted screenshots of an announcement<\/a>&nbsp;on Twitter in which BlackCat said its ransomware \u201chas been completely rewritten from scratch\u201d and that the \u201cmain priority of this update was to optimize detection by AV\/EDR (anti-virus\/endpoint detection and response).\u201d<\/p>\n<p>\u201cSphynx differs from the previous variants in notable ways,\u201d IBM Security X-Force\u2019s analysis said.<\/p>\n<p>\u201cFor example, the command line arguments have been reworked. Previous variants utilized the \u2013access-token parameter in order to execute. The updated ransomware removes that parameter and adds a set of more complex arguments. This makes it harder to detect since defenders do not have standard commands to hunt.\u201d<\/p>\n<p>BlackCat switched to the Rust programming language in 2022, probably because it provided more opportunities to customize malware and hamper efforts to detect and analyze it, and the group\u2019s affiliates continued to abuse the functionality of Group Policy Objects (GPO), both to deploy tools and to interfere with security measures, the researchers said.<\/p>\n<h2>Fast and furious<\/h2>\n<p>\u201cAttackers displaying a nuanced understanding of Active Directory can abuse GPOs to great effect for swift mass malware deployment. For example, threat actors may attempt to increase the speed of their operations by changing default Group Policy refresh times, likely to shorten the window of time between changes taking effect and defenders being able to respond.\u201d<\/p>\n<p>BlackCat attacks generally involved deploying tools for both data encryption and theft because the group usually ran a double extortion scheme.<\/p>\n<p>\u201cX-Force observed attackers leveraging ExMatter, a .NET data exfiltration tool that was introduced in 2021 and received a substantial update in August 2022. ExMatter is exclusively used by one BlackCat ransomware affiliate cluster, tracked by Microsoft as DEV-0504,\u201d the researchers said.<\/p>\n<p>\u201cIBM X-Force has observed evidence that multiple terabytes of data had been exfiltrated from a victim environment to threat actor-controlled infrastructure. Stolen data is frequently posted publicly on the group\u2019s official leak site in an attempt to apply pressure on extortion victims.\u201d<\/p>\n<p>In line with the <a href=\"https:\/\/www.scmagazine.com\/analysis\/cybercrime\/infiltration-of-qilin-reveals-customizable-nature-of-raas-marketplace\">more sophi<\/a><a href=\"https:\/\/www.scmagazine.com\/analysis\/cybercrime\/infiltration-of-qilin-reveals-customizable-nature-of-raas-marketplace\" target=\"_blank\" rel=\"noreferrer noopener\">sticated tools<\/a> other ransomware groups are deploying, X-Force said it expected BlackCat to continue increasing the speed and stealth of it operations using \u201cnovel means to accomplish different stages of their attacks\u201d.<\/p>\n<p>\u201cContinuous advancements in BlackCat ransomware associated tradecraft, as well as the design of BlackCat and ExMatter malware, underscore adversary understanding of target systems and defender processes \u2014 as well as potential points where these can be leveraged for attacker advantage,\u201d researchers wrote.<\/p>\n<p>READ MORE <a href=\"https:\/\/packetstormsecurity.com\/news\/view\/34686\/BlackCat-Updates-Tradecraft-With-Stealth-And-Speed.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":52175,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[277],"tags":[9615],"class_list":["post-52174","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity-blogs","tag-headlinehackermalwarecryptography"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>BlackCat Updates Tradecraft With Stealth And Speed 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/blackcat-updates-tradecraft-with-stealth-and-speed\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"BlackCat Updates Tradecraft With Stealth And Speed 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/blackcat-updates-tradecraft-with-stealth-and-speed\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2023-06-02T15:48:52+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/files.scmagazine.com\/wp-content\/uploads\/2023\/06\/cat-black-panther.jpg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/blackcat-updates-tradecraft-with-stealth-and-speed\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/blackcat-updates-tradecraft-with-stealth-and-speed\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"BlackCat Updates Tradecraft With Stealth And Speed\",\"datePublished\":\"2023-06-02T15:48:52+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/blackcat-updates-tradecraft-with-stealth-and-speed\\\/\"},\"wordCount\":690,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/blackcat-updates-tradecraft-with-stealth-and-speed\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/06\\\/blackcat-updates-tradecraft-with-stealth-and-speed.jpg\",\"keywords\":[\"headline,hacker,malware,cryptography\"],\"articleSection\":[\"CyberSecurity Blogs\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/blackcat-updates-tradecraft-with-stealth-and-speed\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/blackcat-updates-tradecraft-with-stealth-and-speed\\\/\",\"name\":\"BlackCat Updates Tradecraft With Stealth And Speed 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/blackcat-updates-tradecraft-with-stealth-and-speed\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/blackcat-updates-tradecraft-with-stealth-and-speed\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/06\\\/blackcat-updates-tradecraft-with-stealth-and-speed.jpg\",\"datePublished\":\"2023-06-02T15:48:52+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/blackcat-updates-tradecraft-with-stealth-and-speed\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/blackcat-updates-tradecraft-with-stealth-and-speed\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/blackcat-updates-tradecraft-with-stealth-and-speed\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/06\\\/blackcat-updates-tradecraft-with-stealth-and-speed.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/06\\\/blackcat-updates-tradecraft-with-stealth-and-speed.jpg\",\"width\":800,\"height\":533},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/blackcat-updates-tradecraft-with-stealth-and-speed\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"headline,hacker,malware,cryptography\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/headlinehackermalwarecryptography\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"BlackCat Updates Tradecraft With Stealth And Speed\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"BlackCat Updates Tradecraft With Stealth And Speed 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/blackcat-updates-tradecraft-with-stealth-and-speed\/","og_locale":"en_US","og_type":"article","og_title":"BlackCat Updates Tradecraft With Stealth And Speed 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/blackcat-updates-tradecraft-with-stealth-and-speed\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2023-06-02T15:48:52+00:00","og_image":[{"url":"https:\/\/files.scmagazine.com\/wp-content\/uploads\/2023\/06\/cat-black-panther.jpg","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/blackcat-updates-tradecraft-with-stealth-and-speed\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/blackcat-updates-tradecraft-with-stealth-and-speed\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"BlackCat Updates Tradecraft With Stealth And Speed","datePublished":"2023-06-02T15:48:52+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/blackcat-updates-tradecraft-with-stealth-and-speed\/"},"wordCount":690,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/blackcat-updates-tradecraft-with-stealth-and-speed\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2023\/06\/blackcat-updates-tradecraft-with-stealth-and-speed.jpg","keywords":["headline,hacker,malware,cryptography"],"articleSection":["CyberSecurity Blogs"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/blackcat-updates-tradecraft-with-stealth-and-speed\/","url":"https:\/\/www.threatshub.org\/blog\/blackcat-updates-tradecraft-with-stealth-and-speed\/","name":"BlackCat Updates Tradecraft With Stealth And Speed 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/blackcat-updates-tradecraft-with-stealth-and-speed\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/blackcat-updates-tradecraft-with-stealth-and-speed\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2023\/06\/blackcat-updates-tradecraft-with-stealth-and-speed.jpg","datePublished":"2023-06-02T15:48:52+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/blackcat-updates-tradecraft-with-stealth-and-speed\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/blackcat-updates-tradecraft-with-stealth-and-speed\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/blackcat-updates-tradecraft-with-stealth-and-speed\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2023\/06\/blackcat-updates-tradecraft-with-stealth-and-speed.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2023\/06\/blackcat-updates-tradecraft-with-stealth-and-speed.jpg","width":800,"height":533},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/blackcat-updates-tradecraft-with-stealth-and-speed\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"headline,hacker,malware,cryptography","item":"https:\/\/www.threatshub.org\/blog\/tag\/headlinehackermalwarecryptography\/"},{"@type":"ListItem","position":3,"name":"BlackCat Updates Tradecraft With Stealth And Speed"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/52174","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=52174"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/52174\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/52175"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=52174"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=52174"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=52174"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}