Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors black x

Also known as: tracked as, Professor X, Abyss

Description

Known victims: 5

Goals & Targeting

Objectives

Ransomware
Financial Gain

Targeted Sectors

Defense
Manufacturing
Government
Financial services
Retail
Critical infrastructure

Targeted Countries / Regions

RU

AI Analysis

· 1 week ago

Executive Summary

Black X is a medium-sophisticated criminal threat actor specializing in ransomware attacks with a primary focus on financial gain. Known for targeting various sectors including healthcare, legal, and IT through campaigns such as Daechang Solution and Wonjin Plastic Surgery, Black X poses an ongoing risk to organizations globally. With recent activity tracked up to July 2026, they continue to adapt their strategies to maximize disruption and financial extraction.

Goals & Targeting

Black X targets various sectors to maximize victim diversity and potential financial gain. Their strategic approach suggests they focus on industries with high payout potential and vulnerability to disruption. The selection of specific entities within these sectors indicates a tactical method to ensure successful ransom demands, aligning with their objective of organizational-gain and financial extraction.

Enhanced Description

Black X operates as a cybercriminal group primarily motivated by financial gain, employing ransomware as their main tool for extortion. Their campaigns have targeted diverse sectors such as healthcare, legal services, and IT, indicating strategic selection of vulnerable organizations regardless of geographical boundaries. The threat actor has demonstrated adaptability in attack methods, shifting from traditional ransomware to more persistent operations, including data theft and prolonged internal network diffusion.

Key Capabilities

  • Ransomware deployment
  • Network intrusion techniques
  • Spear-phishing campaigns
  • Internal network propagation

MITRE ATT&CK Tactics

Exfiltration of Data
Data Destruction
Impersonation

ATT&CK Techniques

T1059.003 - Spear phishing Attachment
T1566.001 - Data Encrypted for Impact
T1254 - Use of Web Service
T1078.001 Malware

Software / Tooling

Cobalt Strike
Double extortion ransomware
Phishing Kits

Campaigns & Victims

Black X's campaigns, including 'Daechang Solution' and 'Wonjin Plastic Surgery', exhibit targeted attacks across sectors. Their operational tempo suggests a shift towards prolonged internal network diffusion, indicating evolving tactics beyond initial ransom demands to include data theft.

IOC Patterns

  • Phishing emails with malicious links
  • Encrypted files and network traffic spikes
  • Use of C2 servers for command

Recommended Actions

  • Strengthen email filtering and phishing detection
  • Implement endpoint detection and response solutions
  • Conduct regular data backups in secure locations
  • Educate employees on recognizing phishing attempts

Suggested Tags

Criminal
Ransomware
Financial Gain
Global

Confidence Assessment

Moderate confidence in Black X's identity and TTPs, with limited details on specific tools or attack lifecycle. Campaign data suggests varied targeting but lacks comprehensive insights into their operational tactics beyond what is observed.

Campaigns / Victims

Observed Data

No observed data linked yet.

References

  1. www.paloaltonetworks.de — Cited by web research for: T1204
  2. www.paloaltonetworks.com — Cited by web research for: WildFire
  3. pmc.ncbi.nlm.nih.gov — Cited by web research for: BELLHOP

Intel Summary

4

Techniques

32

Tools

8

Campaigns

40

IOCs

0

Observed Data

2

Tactics

Tags

Criminal
Ransomware
Financial Gain
Global

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Country of Origin
Russia (RU)
Confidence
80%
Last Seen
Jul 24, 2026
Added
Jul 13, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.