Also known as: SN Blackmeta, ALPHV, Noberus, Black Metal, Com, Comm, Occultus, numerous other pseudonyms, AuKill, SN_BlackMeta, appeared in November 2023, DarkMeta, malicious actors, APT groups, hackers, services, public key cryptography, one private, the file association, handler, Netshell, header, magic bytes, the IconEnvironmentDataBlock, metamorphic, mutating code, No associated aliases
Blackmeta surfaced publicly in late 2023 as a pro‑Palestinian hacktivist organization that openly claims responsibility for acts of cyber sabotage directed at entities it views as supporting Israeli policies. While the group’s public statements emphasize political goals, subsequent activity reports show a clear capability to profit from traditional revenue streams such as ransomware, business‑email compromise, and cryptocurrency exploitation. Operationally Blackmeta demonstrates a mix of disruptive and destructive tactics: a six‑day, 14.7 million requests‑per‑second DDoS assault against a UAE bank; website defacement and data exfiltration campaigns that employ spearphishing from compromised credentials; and the deployment of malicious cloud container images to achieve persistence on AWS, GCP, Azure and local Docker hosts. The threat actor also employs environmental keying—cryptographic checks that allow payloads to execute only in specific host contexts—and uses process hollowing, BITS jobs, and various command‑and‑scripting interpreters (PowerShell, Python, MSBuild) to move laterally, exfiltrate data, and deliver ransomware such as BlackCat/BlackByte. These techniques enable the group to achieve both political disruption and financial gain. The convergence of hacktivist messaging with monetized capabilities places Blackmeta among the more sophisticated threat groups that are expanding beyond pure ideological motives to exploit modern cloud infrastructures and malware ecosystems.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Blackmeta is a pro‑Palestinian hacktivist group that blends ideological activism with financial theft, targeting Israeli allies and other organizations in the Middle East. The group has executed high‑volume DDoS campaigns, leveraged environmental keying to evade defenses, and deployed cloud‑based persistence mechanisms to facilitate ransomware and business‑email compromise attacks.
Goals & Targeting
Blackmeta aims to punish organizations perceived as supporters of Israeli interests while simultaneously extracting monetary value through ransomware, business‑email compromise, and cryptocurrency theft. The actor focuses on the media, financial services, defense contractors, government entities, critical infrastructure, and IT firms—particularly in the Middle East (notable victims include UAE banks) and Russia. Its operational tempo is rapid, with high‑impact DDoS spikes followed by credential‑stealing or ransomware phases designed to maximize both public visibility and profit. The group’s targeting reflects a dual narrative of political dissent and economic opportunism.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Known operations include a six‑day, 14.7 million requests-per-second DDoS against a UAE bank that overwhelmed target servers for over forty hours. The group also undertook website defacement of media outlets and government sites, followed by data exfiltration efforts using spearphishing through compromised accounts. Their tactics display a rapid attack cycle: initial compromise via phishing or public cloud image exploitation, lateral move using stolen credentials, execution of cryptally‑protected malware, persistence via container images, and final monetization through ransomware or BEC. Recent reports suggest the group continues to target financial institutions, defense contractors and critical infrastructure in the Middle East and Russia.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The available intelligence is derived from publicly released reports and a limited set of IOC samples, providing moderate confidence in the group’s DDoS and environmental‑keying capabilities. Attribution to Blackmeta remains somewhat ambiguous due to overlapping aliases and shared techniques with other actors. Gaps persist regarding the full scope of financial operations, infrastructure details, and long‑term strategic objectives beyond known campaigns.
No campaigns linked yet.
No observed data linked yet.
50
Techniques
46
Tools
0
Campaigns
39
IOCs
0
Observed Data
14
Tactics