# BlackSuit affiliate

> As of 2026-06-06, BlackSuit affiliate is a threat actor tracked by Threadlinqs Intelligence across 2 threats spanning malware. Also known as BlackSuit, Royal, Storm-1811, Black Basta successor. ATT&CK coverage spans 40 techniques across 12 tactics in 2 of 2 tracked threats. Most-observed techniques: T1005 (Data from Local System), T1016 (System Network Configuration Discovery), T1056 (Input Capture).

- **Tracked threats:** 2
- **Categories:** MALWARE
- **Also known as:** BlackSuit, Royal, Storm-1811, Black Basta successor, 3AM-aligned
- **As of:** 2026-06-06

## ATT&CK techniques observed

40 techniques observed across 2 of 2 tracked threats. Tactics: Command and Control (7), Discovery (7), Stealth (formerly Defense Evasion) (5), Execution (4), Exfiltration (4), Collection (3).

- [T1005](https://intel.threadlinqs.com/technique/T1005) Data from Local System — Collection — observed in 2 of 2 tracked threats
- [T1016](https://intel.threadlinqs.com/technique/T1016) System Network Configuration Discovery — Discovery — observed in 2 of 2 tracked threats
- [T1056](https://intel.threadlinqs.com/technique/T1056) Input Capture — Credential Access — observed in 2 of 2 tracked threats
- [T1059](https://intel.threadlinqs.com/technique/T1059) Command and Scripting Interpreter — Execution — observed in 2 of 2 tracked threats
- [T1071](https://intel.threadlinqs.com/technique/T1071) Application Layer Protocol — Command and Control — observed in 2 of 2 tracked threats
- [T1102](https://intel.threadlinqs.com/technique/T1102) Web Service — Command and Control — observed in 2 of 2 tracked threats
- [T1113](https://intel.threadlinqs.com/technique/T1113) Screen Capture — Collection — observed in 2 of 2 tracked threats
- [T1140](https://intel.threadlinqs.com/technique/T1140) Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion) — observed in 2 of 2 tracked threats
- [T1199](https://intel.threadlinqs.com/technique/T1199) Trusted Relationship — Initial Access — observed in 2 of 2 tracked threats
- [T1204](https://intel.threadlinqs.com/technique/T1204) User Execution — Execution — observed in 2 of 2 tracked threats
- [T1219](https://intel.threadlinqs.com/technique/T1219) Remote Access Tools — Command and Control — observed in 2 of 2 tracked threats
- [T1547](https://intel.threadlinqs.com/technique/T1547) Boot or Logon Autostart Execution — Persistence — observed in 2 of 2 tracked threats
- [T1564](https://intel.threadlinqs.com/technique/T1564) Hide Artifacts — Stealth (formerly Defense Evasion) — observed in 2 of 2 tracked threats
- [T1566](https://intel.threadlinqs.com/technique/T1566) Phishing — Initial Access — observed in 2 of 2 tracked threats
- [T1567](https://intel.threadlinqs.com/technique/T1567) Exfiltration Over Web Service — Exfiltration — observed in 2 of 2 tracked threats

## Tracked threats

- [Nimbus RAT (BackupBOX) — Microsoft Teams Vishing + Quick Assist Delivery of a Self-Contained Java RAT Using Google Drive/Sheets for C2 (BlackSuit Affiliate)](https://intel.threadlinqs.com/threat/TL-2026-0691) — HIGH
- [Nimbus RAT: Java-based Remote Access Trojan Delivered via Microsoft Teams Vishing, Quick Assist, and Google Drive C2](https://intel.threadlinqs.com/threat/TL-2026-0847) — HIGH

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/BlackSuit%20affiliate
