Recent campaigns suggest Hamas-linked actors may be advancing their TTPs to include intricate social engineering lures specially crafted to appeal to a niche group of high value targets. In September 2023, a Palestine-based group likely linked to Hamas targeted Israeli software engineers using an elaborate social engineering ruse that ultimately installed malware and stole cookies. The attackers, which Google’s Threat Analysis Group (TAG) tracks as BLACKATOM, posed as employees of legitimate companies and reached out via LinkedIn to invite targets to apply for software development freelance opportunities. Targets included software engineers in the Israeli military, as well as Israel’s aerospace and defense industry
Targeted Sectors
Executive Summary
Blackatom, tracked by Google's Threat Analysis Group (TAG), is a Hamas-linked threat actor targeting high-value individuals in Israel's defense sector through sophisticated social engineering campaigns. Recent operations include phishing attacks on software engineers using LinkedIn to impersonate legitimate companies and steal sensitive data.
Goals & Targeting
Blackatom's strategic objectives align with broader Hamas-associated operations, likely focusing on espionage and intelligence collection to support geopolitical goals. Their targeting of defense and transportation sectors suggests a focus on compromising national security capabilities. The group's victims are typically high-value individuals in sensitive roles, such as software engineers and military personnel.
Enhanced Description
Blackatom has emerged as a significant threat actor, particularly active in campaigns that target specialized personnel within Israel's defense and aerospace industries. The group's operations are characterized by advanced social engineering techniques that leverage niche professional platforms like LinkedIn. In September 2023, Blackatom targeted Israeli software engineers, including those associated with the military and defense sector, by posing as legitimate recruiters offering freelance opportunities. This campaign highlights a clear shift in their tactics to more specialized and sophisticated methods. The group's primary focus appears to be intelligence gathering and undermining national security through targeted attacks on critical infrastructure personnel.
Key Capabilities
Campaigns & Victims
Blackatom's campaigns demonstrate a clear pattern of targeting high-value individuals in defense-related sectors. Their operations are methodical, with a focus on social engineering and tailored phishing attempts. Notable past operations include the September 2023 attack on Israeli software engineers, which underscores their ability to exploit professional networks for access. The group's evolution in tactics suggests they are continuously refining their approach to evade detection.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in the characterization of Blackatom as a Hamas-linked threat actor based on operational patterns and targeting behavior. Limited technical details about their tools or exact MITRE ATT&CK mappings are available, which introduces some uncertainty regarding their precise capabilities.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics