Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Blackmeta

Also known as: SN Blackmeta, ALPHV, Noberus, Black Metal, Com, Comm, Occultus, numerous other pseudonyms, AuKill, SN_BlackMeta, appeared in November 2023, DarkMeta, malicious actors, APT groups, hackers, services, public key cryptography, one private, the file association, handler, Netshell, header, magic bytes, the IconEnvironmentDataBlock, metamorphic, mutating code, No associated aliases

Description

Blackmeta surfaced publicly in late 2023 as a pro‑Palestinian hacktivist organization that openly claims responsibility for acts of cyber sabotage directed at entities it views as supporting Israeli policies. While the group’s public statements emphasize political goals, subsequent activity reports show a clear capability to profit from traditional revenue streams such as ransomware, business‑email compromise, and cryptocurrency exploitation. Operationally Blackmeta demonstrates a mix of disruptive and destructive tactics: a six‑day, 14.7 million requests‑per‑second DDoS assault against a UAE bank; website defacement and data exfiltration campaigns that employ spearphishing from compromised credentials; and the deployment of malicious cloud container images to achieve persistence on AWS, GCP, Azure and local Docker hosts. The threat actor also employs environmental keying—cryptographic checks that allow payloads to execute only in specific host contexts—and uses process hollowing, BITS jobs, and various command‑and‑scripting interpreters (PowerShell, Python, MSBuild) to move laterally, exfiltrate data, and deliver ransomware such as BlackCat/BlackByte. These techniques enable the group to achieve both political disruption and financial gain. The convergence of hacktivist messaging with monetized capabilities places Blackmeta among the more sophisticated threat groups that are expanding beyond pure ideological motives to exploit modern cloud infrastructures and malware ecosystems.

Goals & Targeting

Targeted Sectors

Media
Financial services
Defense
Government
Critical infrastructure
Construction
Information technology
Manufacturing

Targeted Countries / Regions

AE
RU

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 1 day ago

Executive Summary

Blackmeta is a pro‑Palestinian hacktivist group that blends ideological activism with financial theft, targeting Israeli allies and other organizations in the Middle East. The group has executed high‑volume DDoS campaigns, leveraged environmental keying to evade defenses, and deployed cloud‑based persistence mechanisms to facilitate ransomware and business‑email compromise attacks.

Goals & Targeting

Blackmeta aims to punish organizations perceived as supporters of Israeli interests while simultaneously extracting monetary value through ransomware, business‑email compromise, and cryptocurrency theft. The actor focuses on the media, financial services, defense contractors, government entities, critical infrastructure, and IT firms—particularly in the Middle East (notable victims include UAE banks) and Russia. Its operational tempo is rapid, with high‑impact DDoS spikes followed by credential‑stealing or ransomware phases designed to maximize both public visibility and profit. The group’s targeting reflects a dual narrative of political dissent and economic opportunism.

Enhanced Description

Key Capabilities

  • Distributed Denial‑of‑Service (DDoS) attacks
  • Environmental keying for execution control
  • Persistence via malicious cloud container images (AWS AMI, GCP image, Azure VM, Docker)
  • Malware replication with artifact cleanup
  • Internal spearphishing and lateral movement using compromised accounts
  • Command‑and‑scripting interpreters (PowerShell, python.exe, MSBuild)
  • Remote access backdoors
  • Process hollowing
  • Use of BITS jobs for automated exfiltration

MITRE ATT&CK Tactics

Impact
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Command and Control
Exfiltration

ATT&CK Techniques

T1037
T1105
T1110
T1111
T1119
T1123
T1177?
T1185
T1197
T1217
T1543
T1547
T1557
T1583
T1584
T1586
T1595
T1609
T1612
T1613
T1619
T1650
T1651
T1654?
T1708?
T1500?
T1526
T1531
T1555
T1559
T1560
T1571?
T1698?
T1496

Software / Tooling

BlackCat (BlackByte ransomware)
Black Basta
BlackMeta ransomware
Alphv
BlackMatter
MSBuild
PowerShell
python.exe
rundll32.exe
netsh.exe
BITS Job

Campaigns & Victims

Known operations include a six‑day, 14.7 million requests-per-second DDoS against a UAE bank that overwhelmed target servers for over forty hours. The group also undertook website defacement of media outlets and government sites, followed by data exfiltration efforts using spearphishing through compromised accounts. Their tactics display a rapid attack cycle: initial compromise via phishing or public cloud image exploitation, lateral move using stolen credentials, execution of cryptally‑protected malware, persistence via container images, and final monetization through ransomware or BEC. Recent reports suggest the group continues to target financial institutions, defense contractors and critical infrastructure in the Middle East and Russia.

IOC Patterns

  • Domain-based indicators of malicious infrastructure (e.g., demo-cloud.space)
  • Suspicious email forwarding rules established on victim accounts
  • Large‑scale HTTP request spikes indicative of DDoS activity

Recommended Actions

  • Deploy DDoS mitigation such as rate limiting and Web Application Firewalls to block high‑volume attacks.
  • Monitor network traffic for sudden spikes in request rates or anomalous patterns.
  • Audit all email accounts for unauthorized auto‑forwarding rules and disable them immediately.
  • Implement endpoint detection and response solutions that alert on execution of suspicious binaries (rundll32.exe, svchost.exe).
  • Enable multi‑factor authentication and enforce least privilege to protect privileged credentials.
  • Block the execution of unapproved scripts or binaries via application whitelisting.
  • Segment networks and isolate critical assets to limit lateral movement.
  • Apply continuous patching and hardening against known vulnerabilities used in cloud images.

Suggested Tags

pro-Palestinian
hacktivist
DDoS attacker
Blackmeta
environmental-keying
financial-theft
container-persistence
internal-spearphishing
ransomware
BEC
cryptocurrency-extortion

Confidence Assessment

The available intelligence is derived from publicly released reports and a limited set of IOC samples, providing moderate confidence in the group’s DDoS and environmental‑keying capabilities. Attribution to Blackmeta remains somewhat ambiguous due to overlapping aliases and shared techniques with other actors. Gaps persist regarding the full scope of financial operations, infrastructure details, and long‑term strategic objectives beyond known campaigns.

ATT&CK Techniques

Exfiltration
1 technique
Initial Access
1 technique
Privilege Escalation
1 technique
Reconnaissance
1 technique

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. attack.mitre.org — Cited by web research for: services
  2. www.microsoft.com — Cited by web research for: No associated aliases
  3. attack.mitre.org — Cited by web research for: phishing
  4. techdocs.broadcom.com — Cited by web research for: Carbon
  5. www.group-ib.com — Cited by web research for: Manufacturing
  6. https://ctid.mitre.org/projects/top-attack-techniques/ — Cited by AI analysis.

Intel Summary

50

Techniques

46

Tools

0

Campaigns

39

IOCs

0

Observed Data

14

Tactics

Tags

Data Exfiltration
DDoS
Hacktivism
Political motivators
Financial sector
pro-Palestinian
hacktivist
DDoS attacker
Blackmeta
environmental-keying
financial-theft
container-persistence
internal-spearphishing
ransomware
BEC
cryptocurrency-extortion

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
P
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.