Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors BlackJack

Also known as: 21, Storm-0978, Tropical Scorpius, UNC2596, Crouching Yeti, Berserk Bear, Dragonfly, Head Mare, YoroTrooper, SturgeonPhisher, Silent Lynx, Comrade Saiga, Tomiris, ShadowSilk, Transparent Tribe, UNC1549, Smoke Sandstorm, TA455, Imperial Kitten, 0ktapus, Octo Tempest, Scattered Spider, UNC961, Prophet Spider

Description

Blackjack, a threat actor linked to Ukraine's security apparatus, has targeted critical Russian entities such as ISPs, utilities, and military infrastructure. They have claimed responsibility for launching cyberattacks resulting in substantial damage and data exfiltration. The group allegedly used the Fuxnet malware to target sensor gateways connected to internet-connected sensors, impacting infrastructure monitoring systems. Blackjack has also been involved in attacks against companies like Moscollector, causing disruptions and stealing sensitive data.

Goals & Targeting

Targeted Sectors

Telecommunications
Manufacturing
Financial services
Defense
Government
Critical infrastructure
Transportation
Education
Energy
Healthcare
Retail
Oil gas
Aerospace
Aviation
Media
Mining
Food agriculture
Construction
Utilities
Entertainment
Gaming
Legal services
Hospitality
Chemical

Targeted Countries / Regions

RU
UA
US
BY
KZ
BR
AU
CN
TW
CA
SG
VN
TR
PL
JP
GB
EG
IR

AI Analysis

· 1 week ago

Executive Summary

BlackJack is a threat actor linked to Ukraine's security apparatus, known for targeting critical Russian infrastructure, including ISPs, utilities, and military systems. The group has claimed responsibility for cyberattacks using malware like Fuxnet, causing infrastructure disruptions and data breaches. Their actions suggest a strategic intent to undermine Russian operations through targeted cyberespionage and sabotage.

Goals & Targeting

BlackJack's primary objective appears to be destabilizing Russian infrastructure and operations through cyberespionage and sabotage. By targeting ISPs, utilities, and military entities, the group seeks to cripple critical systems, hinder communication, and gather intelligence on high-value assets. The focus on Russia likely reflects geopolitical tensions, with the actor aiming to weaken national infrastructure and extract data that could be used for strategic or economic advantage. Typical victims include organizations involved in energy, defense, and telecommunications, suggesting a deliberate effort to disrupt economic and military capabilities.

Enhanced Description

BlackJack, a threat actor allegedly connected to Ukraine's security apparatus, has emerged as a significant player in state-sponsored cyber operations against Russian entities. The group has specifically targeted critical infrastructure sectors such as internet service providers, energy utilities, and military systems, with attacks aimed at disrupting operations and exfiltrating sensitive data. Notably, BlackJack has used the Fuxnet malware to compromise sensor gateways linked to internet-connected monitoring systems, leading to the degradation of infrastructure oversight. The group has also been implicated in attacks on companies like Moscollector, resulting in operational disruptions and the theft of confidential information. These activities underscore a coordinated effort to impact Russia's critical systems, potentially as part of a broader geopolitical strategy. While no formal attribution has been publicly confirmed, the technical capabilities and targeting patterns align with state-sponsored operations.

Key Capabilities

  • Exploitation of IoT and sensor gateway vulnerabilities
  • Deployment of custom malware (e.g., Fuxnet) for infrastructure disruption
  • Data exfiltration from compromised systems
  • Targeted attacks on critical infrastructure sectors
  • Cyberespionage against high-value Russian entities

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Discovery
Lateral Movement
Data Exfiltration

ATT&CK Techniques

T1210.001 - Exploitation of Remote Code Execution Vulnerabilities
T1530 - Data Exfiltration via Unsecured Channels
T1071.004 - Command and Control over Non-Standard Protocols
T1068 - Privilege Escalation through Exploited Vulnerabilities

Software / Tooling

Fuxnet malware

Campaigns & Victims

BlackJack's campaigns demonstrate a focus on Russian infrastructure, with operations typically targeting industrial and government systems. The group's operational tempo appears to align with geopolitical events, suggesting a strategic, rather than opportunistic, approach. Notable operations include attacks on Moscollector and the deployment of Fuxnet to disrupt sensor networks. Campaigns often involve multi-stage attacks, combining malware deployment with data exfiltration, and leverage vulnerabilities in IoT devices to infiltrate networks.

IOC Patterns

  • Exploitation of vulnerable IoT sensor gateways
  • C2 communication via non-standard industrial protocols
  • Deployment of Fuxnet malware on networked infrastructure devices
  • Unusual traffic patterns indicative of data exfiltration from critical infrastructure

Recommended Actions

  • Implement network segmentation to isolate critical infrastructure systems.
  • Deploy intrusion detection systems to monitor for Fuxnet malware signatures.
  • Conduct regular vulnerability assessments on IoT and sensor gateway devices.
  • Enhance monitoring for anomalous data exfiltration patterns from networked infrastructure.
  • Train personnel on identifying spear-phishing attempts and social engineering tactics.

Suggested Tags

APT
state-sponsored
cyberespionage
critical infrastructure
Ukraine-linked
Russia-targeted

Confidence Assessment

Confidence in the data is moderate, based on the group's claimed responsibility for attacks and the observable use of Fuxnet malware. However, definitive attribution to Ukraine's security apparatus remains unconfirmed, and gaps exist regarding the full scope of the actor's TTPs, command structure, and long-term operational goals.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. ics-cert.kaspersky.com — Cited by web research for: Storm-0978
  2. www.dragos.com — Cited by web research for: VOLTZITE
  3. attack.mitre.org — Cited by web research for: Poland
  4. attack.mitre.org — Cited by web research for: Iran

Intel Summary

6

Techniques

40

Tools

0

Campaigns

26

IOCs

0

Observed Data

1

Tactics

Tags

Data Exfiltration
Government Targeting
APT
state-sponsored
cyberespionage
critical infrastructure
Ukraine-linked
Russia-targeted

Details

Type
Unknown
Resource Level
Unknown
Primary Motivation
Financial gain
Country of Origin
U
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.