Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Blackwater

| Active

Blackwater is a ransomware group that first surfaced in early 2026, combining file encryption with data theft and targeting healthcare organizations, with known victims including Minidoka Memorial Hospital in Idaho.

Victims
6
 
First Discovered
2026-05-02
victim
Last Discovered
2026-05-02
victim
Inactive Since
12
days
Avg Delay
15.6
days
Infostealer
60.0%
victims with domain
Countries
4
hit
View Victims on World Map View Group Statistics
Attack Velocity — Last 12 months
-75% vs last month

Known Locations (1)
Favicon Title Type Available Last Visit Server Info FQDN
favicon Blog Yes 2026-05-14T19:46:42 NGINX nginx ejzl7cjxmkx7lzhiqwidmrwtfjv45pkczbc4fnyaut3t7gll3yaiq5id.onion

Target
Top 5 Activity Sectors
  • Healthcare 2
  • Manufacturing 2
  • Business Services 1
  • Public Sector 1
Top 5 Countries
  • US flag United States 2
  • CN flag China 2
  • TR flag Türkiye 1
  • BR flag Brazil 1

Heatmap

Ransom Notes (1)

YARA Rules (1)

Victims (6)
Logo
Discovered: 2026-05-02 (12d ago)  ·  Attack est.: 2026-03-20
Medical Park Hastaneler Grubu is Turkey's leading healthcare group, operating 36 hospitals across 14…
Logo
Discovered: 2026-05-02 (12d ago)  ·  Attack est.: 2026-04-17
Data will be published after 7 days.…
Logo
Discovered: 2026-05-02 (12d ago)  ·  Attack est.: 2026-04-17
All data will be published soon...…
Logo
Discovered: 2026-05-02 (12d ago)  ·  Attack est.: 2026-04-29
Shenzhen Gongjin Electronics, founded in 1998 and also known as T&W, is a telecommunications manufac…
Logo
Discovered: 2026-05-02 (12d ago)  ·  Attack est.: 2026-04-30
Compass Housing Alliance is dedicated to developing and providing essential services, shelter, and a…
Logo
Discovered: 2026-05-02 (12d ago)
Founded in 1983 and headquartered in Ningbo, China, Ningbo Tuopu Group Co., Ltd. is a multipurpose e…