Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors BlackMaskers

Also known as: BlackMaskers Team, tracked as, the Newscaster Team, dies Februtas, named after the, BlackCat, Gookee, kapuchin0, Guki, leaked the source code, shut the operation down, Black Indians, Royal Ransomware

Description

BlackMaskers Team—also known as BlackMaskers or Newscaster Team—has recently gained notoriety for striking high‑profile Jordanian entities such as the national stock exchange and private sector enterprises. Their operations primarily exploit vulnerabilities in web platforms, executing defacement and data exfiltration to disrupt service availability. The group’s modus operandi extends beyond local targets; they have successfully breached Saudi Arabian websites, indicating a broader regional focus. BlackMaskers appears to employ a mixed technical arsenal that encompasses phishing‐based credential theft, exploitation of public‑facing services (e.g., web framework weaknesses), and the potential use of Ransomware‑as‑a‑Service templates (evidenced by associations with BlackCat, BlackBasta, and RansomHub). Their attacks suggest a capability to perform rapid lateral movement and persistence across compromised systems. Politically aligned with the heightened tensions between Israel and Iran, BlackMaskers selectively targets sectors that could yield both financial returns and strategic influence—especially finance, defense, critical infrastructure, and telecommunications. The group likely acts opportunistically, striking when public‑facing applications can be exploited or when phishing spear‑phases are successful. While their precise geographic and operational scope remains partially opaque, multiple reports confirm activity in the Middle East, with an expanding footprint into EU and North American targets. Their ongoing use of dynamic staging domains (e.g., TEMP.*, PROXY.AM) underscores a modern threat actor approach that emphasizes resilience against takedown efforts.

Goals & Targeting

Targeted Sectors

Financial services
Government
Critical infrastructure
Defense
Telecommunications
Education
Healthcare
Manufacturing
Media
Maritime
Retail
Non profit
Hospitality
Food agriculture
Aerospace
Information technology
Entertainment
Energy
Nuclear
Gaming
Construction
Transportation

Targeted Countries / Regions

AE
IL
RU
IR
GB
UA
IN
CN
KP
DE
PK
BY
PL
TW
CA
AU

AI Analysis

Grounded in web research
· 22 hours ago

Executive Summary

BlackMaskers is an emerging, financially‑motivated threat actor that has targeted critical infrastructure in Jordan and Saudi Arabia amid the Israel–Iran conflict. The group conducts website defacement, data breaches, and likely ransomware attacks leveraging public‑facing application exploits and phishing campaigns.

Goals & Targeting

BlackMaskers seeks to maximize financial gain through extortion, theft, or revenue leakage while also amplifying geopolitical pressure in the Middle East. Their focus on finance, defense, critical infrastructure and high‑traffic web services allows them to exploit both valuable data sets and politically sensitive assets. Typical victims are government agencies, national exchanges, private sector enterprises with public interfaces, and corporate websites that lack robust security controls.

Enhanced Description

Key Capabilities

  • Web application exploitation (public‑facing app attacks)
  • Website defacement and content injection
  • Credential theft via infostealers (e.g., Agent Tesla, Keycat)
  • Phishing campaigns using malicious attachments or links
  • Data exfiltration over web services and alternative protocols
  • Use of dynamic DNS/staging domains for C2 persistence
  • Ransomware deployment through RaaS channels (BlackCat/BlackBasta)
  • Exploitation of remote services (T1133) and stolen credentials (T1552)

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Command and Control
Exfiltration
Impact

ATT&CK Techniques

T1560.001
T1560
T1036
T1190
T1133
T1059.003
T1140
T1048
T1525
T1559.002
T1486
T1657
T1078
T1081

Software / Tooling

BlackCat
BlackBasta
RansomHub
Agent Tesla
Mimikatz
Havex RAT
Cobalt Strike
Mythic
HELLOKITTY
DarkSide
Royal Ransomware
BlackByte Ransomware

Campaigns & Victims

The group’s known campaigns center on opportunistic attacks in geopolitical hotspots, starting with the Jordanian stock exchange defacement and a broader assault on Saudi web services. They demonstrate rapid campaign initiation following exploitation of public vulnerabilities. Victims range from state financial institutions to private sector firms; patterns suggest that once an initial foothold is achieved—often via phishing or credential compromise—they expand lateral reach to secure additional high‑value data before executing ransomware or extortion tactics.

IOC Patterns

  • Spear-phishing with malicious attachments or URLs
  • Website defacement through compromised control panels
  • Rapid domain rotation using TEMP.* and PROXY.AM staging domains
  • Exfiltration over secure web services (HTTP/HTTPS)
  • Use of fast‑flux DNS for C2 traffic

Recommended Actions

  • Enforce multi‑factor authentication on all remote and admin access points.
  • Patch public‑facing applications and web frameworks promptly; implement WAF filtering.
  • Block known malicious domains such as Temp.* patterns and PROXY.AM domains via DNS filtering.
  • Deploy advanced email filtering with attachment sandboxing to block phishing campaigns.
  • Maintain regular, offline backups of critical data and test recovery procedures annually.
  • Conduct ongoing employee security awareness training focused on spear‑phishing recognition.

Suggested Tags

APT
cybercrime
ransomware
financial-extortion
Middle East
critical-infrastructure
government-targeting
politically-motivated

Confidence Assessment

The core profile—target sectors, use of phishing and web‑app exploitation, and regional focus—is derived from multiple contemporary reports, indicating high confidence. However, details about specific tools (e.g., exact RaaS variants), internal coordination with other groups, or precise technical procedures are less well documented; these areas warrant lower confidence pending further intelligence.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. unit42.paloaltonetworks.com — Cited by web research for: BlackCat
  2. www.huntress.com — Cited by web research for: phishing
  3. thecyberexpress.com — Cited by web research for: CVE-2026-20316
  4. www.malwarepatrol.net — Cited by web research for: GA.js

Intel Summary

16

Techniques

45

Tools

0

Campaigns

12

IOCs

0

Observed Data

9

Tactics

Tags

Financial Targeting
Data Exfiltration
Hacktivism
APT
geopolitical
espionage
Middle East
finance-sector
critical infrastructure
cybercrime
ransomware
financial-extortion
critical-infrastructure
government-targeting
politically-motivated

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
Iran (IR)
Confidence
60%
Added
Jul 5, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.