Classification: TLP:CLEAR | Publication Date: 2026-10-10 | Source: ransomware.live leak-site monitoring | Nature of data: Unverified threat-actor claims
Executive Summary
On 2026-10-09, the ransomware group BLACK X published three new listings to its dark web leak site, naming lopay (Financial Services, GB), enTouch (Technology, JP), and bayer (Healthcare, DE). Each listing was independently observed by a second leak-site crawler, meaning we can confirm the gang made the claims — but the underlying breaches remain unconfirmed.
The spread across three sectors and three geographies in a single posting day is consistent with BLACK X's established pattern of opportunistic, access-broker-driven operations rather than a focused sector campaign. However, the presence of a payments/financial services firm, a Japanese technology company, and a German healthcare entity in one batch suggests the group is actively monetizing whatever initial access it can acquire — and defenders in all three verticals should treat this as a trigger to hunt for the group's known pre-encryption TTPs, not as confirmation that any specific named organization has an active incident.
Key takeaway for defenders: All three listings are threat-actor assertions. Detection engineering below targets the gang's documented playbook (exposed edge services, PsExec/WMI lateral movement, data staging before detonation) and should be run regardless of whether your organization appears on the list.
Sourcing & Verification
- 3 of 3 listings on BLACK X's leak site were independently observed by a second crawler (MULTI-SOURCE tier). 0 appear on a single source only.
- Inclusion in this briefing reflects the threat actor's claim and is NOT confirmation of a breach. No corroboration tier in our data pipeline confirms that a breach occurred — only the named organization or its regulator can do that.
- A named organization may dispute or deny the listing. A denial is likewise not proof the claim is false: disclosure obligations vary by jurisdiction and incident type, and not every incident is legally reportable. Neither silence nor denial settles the question.
- Security Arsenal will publish corrections if new information emerges and welcomes contact from any named organization at security@securityarsenal.com.
Threat Actor Profile — BLACK X
| Attribute | Assessment |
|---|---|
| Aliases | BLACK X (primary branding); no widely adopted alternate aliases confirmed in open reporting |
| Operating model | Closed-group operation with semi-formalized affiliate relationships for initial access; not a fully open RaaS. Appears to purchase access from brokers rather than recruiting publicly |
| Typical ransom demand | Historically scales to victim revenue; observed demands range from low six figures (SMB) to multi-million USD (enterprise), with negotiation room of 30–60% |
| Initial access methods | (1) Exploitation of exposed edge services — VPN concentrators, firewalls, virtualization management planes; (2) spear-phishing with macro-enabled documents; (3) purchased RDP/VPN credentials from access brokers; (4) opportunistic abuse of CI/CD and developer tooling |
| Extortion model | Double extortion — exfiltration before encryption, leak-site publication as pressure. Data theft typically precedes detonation by days |
| Average dwell time | Estimated 5–14 days from initial access to encryption in observed operations, with the exfiltration/staging phase concentrated in the final 48–72 hours |
Current Campaign Analysis
Sector Targeting
The three listings span Financial Services (lopay, GB), Technology (enTouch, JP), and Healthcare (bayer, DE). This is a deliberately (or opportunistically) diversified batch: payments data, source code/IP, and patient data are the three highest-leverage exfiltration commodities in the extortion economy. BLACK X's leak-site pressure model benefits from victims whose regulatory exposure (FCA, APPI, GDPR/health data) makes non-payment costly.
Geographic Concentration
GB, JP, and DE — three jurisdictions in one day, no regional clustering. This supports the broker-driven hypothesis: the gang is monetizing whatever access is available rather than running a regionally focused intrusion set.
Victim Profile
- lopay — payments-sector firm; mid-market profile typical of UK fintech/payment services.
- enTouch — technology sector, Japan.
- bayer — healthcare sector, Germany. (Name reproduced exactly as posted by the threat actor; no assumption is made about corporate identity or affiliation.)
The mix suggests a victim range from mid-market to large enterprise — consistent with demands scaled from hundreds of thousands into the millions of USD.
Posting Frequency / Escalation
Three listings in a single day is at the upper end of BLACK X's observed cadence. Batch posting of this kind typically indicates a pipeline of concurrently staged intrusions reaching the publish-or-pay decision point simultaneously — which often means other intrusions from the same access wave are still in the pre-encryption phase right now.
CVE Exposure Hypothesis (Sector-Level Only)
We have no evidence linking any specific CVE to any specific named listing. However, BLACK X's known tradecraft aligns with several vulnerabilities currently on the CISA KEV with confirmed ransomware use, and defenders in the targeted sectors should prioritize these as hypothetical entry points:
- CVE-2026-50751 (Check Point Security Gateway, improper authentication in IKEv1) — matches the gang's edge/VPN exploitation pattern.
- CVE-2026-20316 (Cisco Secure Firewall Management Center, hard-coded password) — network management plane compromise enables both access and blind spots.
- CVE-2026-59310 (VMware vCenter path traversal) — virtualization control plane; historically the highest-impact target for ransomware groups because vCenter access enables mass hypervisor-level encryption.
- CVE-2026-63077 (JetBrains TeamCity deserialization) — CI/CD compromise aligns with the Technology-sector listing; build servers are also high-value staging points.
- CVE-2026-48027 (Nx Console embedded malicious code) — developer-tooling supply chain exposure; relevant to technology firms with Node.js/monorepo environments.
Detection Engineering
---
title: BLACK X - PsExec Service Installation for Lateral Movement
id: 7f3a1c2e-4b5d-4e6f-9a0b-blackx00001
status: experimental
description: Detects PsExec-style remote service creation associated with BLACK X lateral movement before ransomware detonation.
author: Security Arsenal Threat Intelligence
references:
- https://securityarsenal.com/darkside
date: 2026/10/10
logsource:
category: service_creation
product: windows
detection:
selection_name:
ServiceName|contains:
- 'PSEXESVC'
- 'PAExec'
selection_path:
ImagePath|contains:
- '\ADMIN$'
- 'PSEXESVC.exe'
condition: selection_name or selection_path
falsepositives:
- Legitimate administrative remote management
level: high
tags:
- attack.lateral_movement
- attack.t1021.002
- attack.t1569.002
---
title: BLACK X - Pre-Encryption Data Staging with Archive Utilities
id: 7f3a1c2e-4b5d-4e6f-9a0b-blackx00002
status: experimental
description: Detects mass archive creation (rar/7z) with password flags on servers, consistent with BLACK X pre-exfiltration staging in the final 48-72 hours before encryption.
author: Security Arsenal Threat Intelligence
references:
- https://securityarsenal.com/darkside
date: 2026/10/10
logsource:
category: process_creation
product: windows
detection:
selection_img:
Image|endswith:
- '\rar.exe'
- '\7z.exe'
- '\7za.exe'
- '\winrar.exe'
selection_cli:
CommandLine|contains:
- ' a '
- ' -hp'
- ' -p'
condition: selection_img and selection_cli
falsepositives:
- Backup administrators packaging logs
level: high
tags:
- attack.collection
- attack.t1560.001
---
title: BLACK X - Volume Shadow Copy Deletion Pre-Ransomware
id: 7f3a1c2e-4b5d-4e6f-9a0b-blackx00003
status: experimental
description: Detects shadow copy deletion via vssadmin, wmic, or PowerShell CIM — a near-universal step in BLACK X detonation chains.
author: Security Arsenal Threat Intelligence
references:
- https://securityarsenal.com/darkside
date: 2026/10/10
logsource:
category: process_creation
product: windows
detection:
selection_vss:
Image|endswith:
- '\vssadmin.exe'
CommandLine|contains:
- 'delete shadows'
selection_wmic:
Image|endswith:
- '\wmic.exe'
CommandLine|contains:
- 'shadowcopy'
- 'delete'
selection_ps:
CommandLine|contains:
- 'Get-WmiObject Win32_Shadowcopy'
- 'Remove-CimInstance'
- 'Win32_ShadowCopy'
condition: 1 of selection_*
falsepositives:
- Storage administrators managing shadow copies
level: critical
tags:
- attack.impact
- attack.t1490
// BLACK X hunt: lateral movement + pre-ransomware staging correlated within 72h
// Microsoft Sentinel / Defender XDR
let window = 72h;
let suspiciousHosts = DeviceProcessEvents
| where Timestamp > ago(window)
| where ProcessCommandLine has_any ("vssadmin delete shadows", "shadowcopy delete", "bcdedit", "recoveryenabled no")
or FileName in~ ("psexec.exe", "psexesvc.exe", "paexec.exe")
| summarize StagingEvents = count(), FirstSeen = min(Timestamp) by DeviceName, AccountName;
let remoteLogons = DeviceLogonEvents
| where Timestamp > ago(window)
| where LogonType in ("RemoteInteractive", "Network")
| where RemoteDeviceName !in ("", "localhost")
| summarize RemoteLogonCount = count(), Sources = make_set(RemoteDeviceName) by DeviceName, AccountName;
suspiciousHosts
| join kind=inner remoteLogons on DeviceName
| project DeviceName, AccountName, StagingEvents, FirstSeen, RemoteLogonCount, Sources
| where StagingEvents >= 1 and RemoteLogonCount >= 3
| order by FirstSeen asc;
# BLACK X rapid triage: new scheduled tasks (7d), exposed RDP, and shadow copy state
# Run as Administrator on suspect hosts or via your RMM/EDR remote shell
Write-Host "=== Scheduled tasks created in the last 7 days ===" -ForegroundColor Cyan
Get-ScheduledTask | ForEach-Object {
$info = Get-ScheduledTaskInfo -TaskName $_.TaskName -TaskPath $_.TaskPath -ErrorAction SilentlyContinue
$reg = Get-ItemProperty "HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree$($_.TaskPath)$($_.TaskName)" -ErrorAction SilentlyContinue
if ($reg -and $reg.SD) {
$task = Get-ScheduledTask -TaskName $_.TaskName -TaskPath $_.TaskPath
$created = ($task | Select-Object -ExpandProperty Date -ErrorAction SilentlyContinue)
}
} | Out-Null
# Simpler reliable approach: pull task creation events from the event log
Get-WinEvent -FilterHashtable @{LogName='Microsoft-Windows-TaskScheduler/Operational'; Id=106; StartTime=(Get-Date).AddDays(-7)} -ErrorAction SilentlyContinue |
Select-Object TimeCreated, Message | Format-List
Write-Host "=== RDP exposure check ===" -ForegroundColor Cyan
$rdpEnabled = (Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server' -Name fDenyTSConnections).fDenyTSConnections
if ($rdpEnabled -eq 0) {
Write-Host "[ALERT] RDP is ENABLED. Verifying NLA and firewall scope..." -ForegroundColor Red
$nla = (Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -Name UserAuthentication -ErrorAction SilentlyContinue).UserAuthentication
Write-Host "NLA required: $nla (1 = required, 0 = NOT required - CRITICAL GAP)"
Get-NetFirewallRule -DisplayGroup 'Remote Desktop' | Where-Object Enabled -eq 'True' |
Select-Object DisplayName, Profile, Direction | Format-Table
} else {
Write-Host "[OK] RDP disabled."
}
Write-Host "=== Volume Shadow Copy integrity ===" -ForegroundColor Cyan
$shadows = Get-CimInstance Win32_ShadowCopy -ErrorAction SilentlyContinue
if (-not $shadows) {
Write-Host "[ALERT] NO shadow copies present - possible anti-recovery action (T1490)." -ForegroundColor Red
} else {
$shadows | Select-Object InstallDate, DeviceObject, VolumeName | Format-Table
}
Write-Host "=== Failed logons (potential brute force) - last 7 days ===" -ForegroundColor Cyan
Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4625; StartTime=(Get-Date).AddDays(-7)} -ErrorAction SilentlyContinue |
Group-Object -Property {$_.Properties[13].Value} |
Where-Object Count -gt 50 |
Sort-Object Count -Descending |
Select-Object Count, Name | Format-Table
Incident Response Priorities
T-Minus Detection Checklist (Before Encryption Fires)
- Shadow copy deletion commands (
vssadmin delete shadows,bcdedit ... recoveryenabled no) — typically minutes to hours before detonation. - Mass archive creation on file servers or database hosts — rar/7z with password flags, especially outside business hours.
- New local/domain admin accounts or unexpected additions to privileged groups.
- PsExec service artifacts (
PSEXESVC) appearing on multiple hosts from a single source — the staging blast radius preview. - Anomalous outbound transfer volume to unfamiliar cloud storage, VPS endpoints, or Mega/file-hosting domains.
- EDR/AV tampering events — service stops, exclusion additions, or uninstall attempts on security tooling.
Critical Assets This Gang Prioritizes for Exfiltration
- Financial/payments data (relevant to the lopay claim): transaction records, KYC documents, settlement files.
- Source code and build pipelines (relevant to the enTouch claim): repositories, CI/CD secrets, signing certificates.
- Patient and clinical data (relevant to the bayer claim): EHR exports, research data, HR/employee records.
- In all cases: executive email archives and legal/contract documents — the extortion leverage layer.
Containment Actions — Ordered by Urgency
- Isolate, don't power off — network-quarantine suspect hosts to preserve memory artifacts.
- Disable compromised/suspect accounts and revoke sessions — including service accounts seen in lateral movement.
- Block egress to staging infrastructure at the proxy/firewall; force DNS sinkholing for identified exfil domains.
- Protect backups — verify offline/immutable copies are truly unreachable from production credentials now, not after detonation.
- Patch the KEV edge devices (Check Point, Cisco FMC, vCenter) on an emergency change window.
- Engage IR retainers and legal counsel early — disclosure clock implications differ across GB (FCA/ICO), JP (APPI), and DE (GDPR/BDSG).
Hardening Recommendations
Immediate (24 Hours)
- Patch or mitigate all five KEV-listed exposures — Check Point IKEv1 auth bypass (CVE-2026-50751), Cisco FMC hard-coded credentials (CVE-2026-20316), vCenter path traversal (CVE-2026-59310), TeamCity deserialization (CVE-2026-63077), Nx Console supply chain (CVE-2026-48027). Where patching isn't possible, restrict management interfaces to allow-listed jump hosts.
- Enforce phishing-resistant MFA (FIDO2) on all remote access — VPN, RDP gateways, and admin portals. Disable RDP from the internet entirely.
- Deploy the Sigma rules above and run the KQL hunt across the last 30 days, not just 72 hours.
- Enable tamper protection on EDR and alert on any exclusion changes.
Short-Term (2 Weeks)
- Segment by blast radius: isolate backup infrastructure behind a separate identity plane; vCenter/ESXi management on a dedicated, firewalled VLAN with no direct user-segment access.
- Deploy egress filtering with default-deny for server subnets — exfiltration is the extortion lever; make bulk outbound transfer loud.
- Harden CI/CD and developer tooling: rotate TeamCity credentials and pipeline secrets, pin/audit VS Code extensions after the Nx Console incident class, and require signed commits for production build paths.
- Tabletop a double-extortion scenario including the "we refuse to pay, data is published" branch — comms, legal, and regulator notification paths per jurisdiction.
Related Resources
Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.