Also known as: 21, Storm-0978, Tropical Scorpius, UNC2596, Crouching Yeti, Berserk Bear, Dragonfly, Head Mare, YoroTrooper, SturgeonPhisher, Silent Lynx, Comrade Saiga, Tomiris, ShadowSilk, Transparent Tribe, UNC1549, Smoke Sandstorm, TA455, Imperial Kitten, 0ktapus, Octo Tempest, Scattered Spider, UNC961, Prophet Spider
Blackjack, a threat actor linked to Ukraine's security apparatus, has targeted critical Russian entities such as ISPs, utilities, and military infrastructure. They have claimed responsibility for launching cyberattacks resulting in substantial damage and data exfiltration. The group allegedly used the Fuxnet malware to target sensor gateways connected to internet-connected sensors, impacting infrastructure monitoring systems. Blackjack has also been involved in attacks against companies like Moscollector, causing disruptions and stealing sensitive data.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
BlackJack is a threat actor linked to Ukraine's security apparatus, known for targeting critical Russian infrastructure, including ISPs, utilities, and military systems. The group has claimed responsibility for cyberattacks using malware like Fuxnet, causing infrastructure disruptions and data breaches. Their actions suggest a strategic intent to undermine Russian operations through targeted cyberespionage and sabotage.
Goals & Targeting
BlackJack's primary objective appears to be destabilizing Russian infrastructure and operations through cyberespionage and sabotage. By targeting ISPs, utilities, and military entities, the group seeks to cripple critical systems, hinder communication, and gather intelligence on high-value assets. The focus on Russia likely reflects geopolitical tensions, with the actor aiming to weaken national infrastructure and extract data that could be used for strategic or economic advantage. Typical victims include organizations involved in energy, defense, and telecommunications, suggesting a deliberate effort to disrupt economic and military capabilities.
Enhanced Description
BlackJack, a threat actor allegedly connected to Ukraine's security apparatus, has emerged as a significant player in state-sponsored cyber operations against Russian entities. The group has specifically targeted critical infrastructure sectors such as internet service providers, energy utilities, and military systems, with attacks aimed at disrupting operations and exfiltrating sensitive data. Notably, BlackJack has used the Fuxnet malware to compromise sensor gateways linked to internet-connected monitoring systems, leading to the degradation of infrastructure oversight. The group has also been implicated in attacks on companies like Moscollector, resulting in operational disruptions and the theft of confidential information. These activities underscore a coordinated effort to impact Russia's critical systems, potentially as part of a broader geopolitical strategy. While no formal attribution has been publicly confirmed, the technical capabilities and targeting patterns align with state-sponsored operations.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
BlackJack's campaigns demonstrate a focus on Russian infrastructure, with operations typically targeting industrial and government systems. The group's operational tempo appears to align with geopolitical events, suggesting a strategic, rather than opportunistic, approach. Notable operations include attacks on Moscollector and the deployment of Fuxnet to disrupt sensor networks. Campaigns often involve multi-stage attacks, combining malware deployment with data exfiltration, and leverage vulnerabilities in IoT devices to infiltrate networks.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the data is moderate, based on the group's claimed responsibility for attacks and the observable use of Fuxnet malware. However, definitive attribution to Ukraine's security apparatus remains unconfirmed, and gaps exist regarding the full scope of the actor's TTPs, command structure, and long-term operational goals.
No campaigns linked yet.
No observed data linked yet.
6
Techniques
40
Tools
0
Campaigns
26
IOCs
0
Observed Data
1
Tactics