Also known as: BlackMaskers Team, tracked as, the Newscaster Team, dies Februtas, named after the, BlackCat, Gookee, kapuchin0, Guki, leaked the source code, shut the operation down, Black Indians, Royal Ransomware
BlackMaskers Team—also known as BlackMaskers or Newscaster Team—has recently gained notoriety for striking high‑profile Jordanian entities such as the national stock exchange and private sector enterprises. Their operations primarily exploit vulnerabilities in web platforms, executing defacement and data exfiltration to disrupt service availability. The group’s modus operandi extends beyond local targets; they have successfully breached Saudi Arabian websites, indicating a broader regional focus. BlackMaskers appears to employ a mixed technical arsenal that encompasses phishing‐based credential theft, exploitation of public‑facing services (e.g., web framework weaknesses), and the potential use of Ransomware‑as‑a‑Service templates (evidenced by associations with BlackCat, BlackBasta, and RansomHub). Their attacks suggest a capability to perform rapid lateral movement and persistence across compromised systems. Politically aligned with the heightened tensions between Israel and Iran, BlackMaskers selectively targets sectors that could yield both financial returns and strategic influence—especially finance, defense, critical infrastructure, and telecommunications. The group likely acts opportunistically, striking when public‑facing applications can be exploited or when phishing spear‑phases are successful. While their precise geographic and operational scope remains partially opaque, multiple reports confirm activity in the Middle East, with an expanding footprint into EU and North American targets. Their ongoing use of dynamic staging domains (e.g., TEMP.*, PROXY.AM) underscores a modern threat actor approach that emphasizes resilience against takedown efforts.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
BlackMaskers is an emerging, financially‑motivated threat actor that has targeted critical infrastructure in Jordan and Saudi Arabia amid the Israel–Iran conflict. The group conducts website defacement, data breaches, and likely ransomware attacks leveraging public‑facing application exploits and phishing campaigns.
Goals & Targeting
BlackMaskers seeks to maximize financial gain through extortion, theft, or revenue leakage while also amplifying geopolitical pressure in the Middle East. Their focus on finance, defense, critical infrastructure and high‑traffic web services allows them to exploit both valuable data sets and politically sensitive assets. Typical victims are government agencies, national exchanges, private sector enterprises with public interfaces, and corporate websites that lack robust security controls.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
The group’s known campaigns center on opportunistic attacks in geopolitical hotspots, starting with the Jordanian stock exchange defacement and a broader assault on Saudi web services. They demonstrate rapid campaign initiation following exploitation of public vulnerabilities. Victims range from state financial institutions to private sector firms; patterns suggest that once an initial foothold is achieved—often via phishing or credential compromise—they expand lateral reach to secure additional high‑value data before executing ransomware or extortion tactics.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The core profile—target sectors, use of phishing and web‑app exploitation, and regional focus—is derived from multiple contemporary reports, indicating high confidence. However, details about specific tools (e.g., exact RaaS variants), internal coordination with other groups, or precise technical procedures are less well documented; these areas warrant lower confidence pending further intelligence.
No campaigns linked yet.
No observed data linked yet.
16
Techniques
45
Tools
0
Campaigns
12
IOCs
0
Observed Data
9
Tactics