Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Blackatom

Description

Recent campaigns suggest Hamas-linked actors may be advancing their TTPs to include intricate social engineering lures specially crafted to appeal to a niche group of high value targets. In September 2023, a Palestine-based group likely linked to Hamas targeted Israeli software engineers using an elaborate social engineering ruse that ultimately installed malware and stole cookies. The attackers, which Google’s Threat Analysis Group (TAG) tracks as BLACKATOM, posed as employees of legitimate companies and reached out via LinkedIn to invite targets to apply for software development freelance opportunities. Targets included software engineers in the Israeli military, as well as Israel’s aerospace and defense industry

Goals & Targeting

Targeted Sectors

Defense
Transportation

AI Analysis

· 1 week ago

Executive Summary

Blackatom, tracked by Google's Threat Analysis Group (TAG), is a Hamas-linked threat actor targeting high-value individuals in Israel's defense sector through sophisticated social engineering campaigns. Recent operations include phishing attacks on software engineers using LinkedIn to impersonate legitimate companies and steal sensitive data.

Goals & Targeting

Blackatom's strategic objectives align with broader Hamas-associated operations, likely focusing on espionage and intelligence collection to support geopolitical goals. Their targeting of defense and transportation sectors suggests a focus on compromising national security capabilities. The group's victims are typically high-value individuals in sensitive roles, such as software engineers and military personnel.

Enhanced Description

Blackatom has emerged as a significant threat actor, particularly active in campaigns that target specialized personnel within Israel's defense and aerospace industries. The group's operations are characterized by advanced social engineering techniques that leverage niche professional platforms like LinkedIn. In September 2023, Blackatom targeted Israeli software engineers, including those associated with the military and defense sector, by posing as legitimate recruiters offering freelance opportunities. This campaign highlights a clear shift in their tactics to more specialized and sophisticated methods. The group's primary focus appears to be intelligence gathering and undermining national security through targeted attacks on critical infrastructure personnel.

Key Capabilities

  • Sophisticated social engineering
  • Targeted phishing campaigns
  • Advanced persistent threat (APT) tactics
  • Malware deployment

Campaigns & Victims

Blackatom's campaigns demonstrate a clear pattern of targeting high-value individuals in defense-related sectors. Their operations are methodical, with a focus on social engineering and tailored phishing attempts. Notable past operations include the September 2023 attack on Israeli software engineers, which underscores their ability to exploit professional networks for access. The group's evolution in tactics suggests they are continuously refining their approach to evade detection.

IOC Patterns

  • Spear-phishing via LinkedIn
  • Tailored social engineering messages
  • Malware installation through compromised accounts
  • Cookie theft and data exfiltration

Recommended Actions

  • Implement advanced phishing detection solutions
  • Enhance employee training on social engineering risks
  • Monitor professional recruitment platforms for suspicious activity
  • Use multi-factor authentication (MFA) for sensitive accounts
  • Conduct regular network monitoring for signs of APT activity

Suggested Tags

APT
espionage
defense-sector
nation-state

Confidence Assessment

High confidence in the characterization of Blackatom as a Hamas-linked threat actor based on operational patterns and targeting behavior. Limited technical details about their tools or exact MITRE ATT&CK mappings are available, which introduces some uncertainty regarding their precise capabilities.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
Government Targeting
espionage
defense-sector
nation-state

Details

Type
Nation-State
Country of Origin
P
Confidence
50%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.