Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors blackshadow

Also known as: Sandworm Team, tracked as, Black Shadow, a dark fleet, is a ship, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, APT28, VOLTZITE, for follow-on operations, Unit 61398, BlackCat, Gookee, kapuchin0, Guki, leaked the source code, shut the operation down, doxing, doxfare, hack, Tech Sectors, November 6, 2023, Marc Salinas Fernandez, Jiri Vinopal, Royal Ransomware, Agrius

Description

BlackShadow is an Iranian-linked hack-and-leak group (linked to the Agrius APT) that targeted Israeli companies including insurance firm Shirbit and hosting provider Cyberserve, leaking medical records of 290,000 patients, using extortion as a tool of geopolitical disruption rather than purely for financial gain. Known victims: 3

Goals & Targeting

Objectives

Ransomware
Financial Gain

Targeted Sectors

Government
Financial services
Telecommunications
Defense
Healthcare
Education
Manufacturing
Media
Non profit
Energy
Critical infrastructure
Information technology
Pharmaceutical
Hospitality
Aerospace
Aviation
Retail
Think tank
Transportation
Legal services
Mining
Chemical
Gaming
Nuclear
Maritime
Entertainment
Construction
Oil gas
Utilities
Food agriculture

Targeted Countries / Regions

US
IL
CN
IR
RU
SA
GB
IN
UA
AE
VN
JP
PK
AU
TW
KR
DE
KP
BY
SG
TR
PL
CA
RO
MX
ES
LB
FR
NG
IT
AZ
KZ

AI Analysis

· 1 week ago

Executive Summary

BlackShadow, a medium-sophistication Iranian-linked hack-and-leak group with ties to the Agrius APT, has emerged as a notable threat actor targeting Israeli organizations. In December 2021, they attacked insurance firm Shirbit and hosting provider Cyberserve, compromising medical records of over 290,000 patients. Unlike typical cybercriminals, BlackShadow's primary motivation appears to be geopolitical disruption through extortion and data leaks, blending financial gain with strategic objectives.

Goals & Targeting

BlackShadow's strategic objectives appear to be twofold: achieving financial gain through ransom demands and causing geopolitical disruption by targeting Israeli entities. Their choice of victims, including insurance firms and hosting providers, indicates a focus on sectors with high exposure to sensitive data that can be weaponized for both monetary and reputational damage. The group's activities are likely intended to exert pressure on Israel's critical infrastructure while demonstrating technical expertise in infiltratingand compromising such targets.

Enhanced Description

BlackShadow is an Iranian-linked cyber threat group known for its hack-and-leak operations, particularly targeting Israeli companies. The group has been associated with the Agrius APT and has demonstrated a focus on critical sectors such as insurance and hosting services. In one notable operation, they targeted Shirbit, an Israeli insurance firm, and Cyberserve, a major hosting provider, resulting in the exposure of sensitive medical records of over 290,000 individuals. This attack highlights BlackShadow's ability to disrupt both financial and healthcare sectors while leveraging data as a tool for extortion and geopolitical pressure. The group's activities suggest a sophisticated operational capacity, likely involving advanced persistent threats (APTs), and their modus operandi includes the use of extortion tactics and data dumping to achieve strategic objectives rather than purely financially motivated ransomware campaigns.

Key Capabilities

  • Advanced persistent threat (APT) capabilities
  • Data exfiltration
  • Ransomware deployment
  • Extortion tactics
  • Geopolitical disruption through data leaks

MITRE ATT&CK Tactics

Initial Access
Execution
Credential Dumping
Lateral Movement
Exfiltration

ATT&CK Techniques

T1059.003
T1055
T1566.001
T1078
T1567

Software / Tooling

Custom ransomware
Dumpzilla (credential dumping)
Cobalt Strike (for C2)

Campaigns & Victims

BlackShadow's campaign in December 2021 demonstrated a rapid operational tempo, targeting multiple high-value organizations within the same timeframe. The group appears to focus on victims with significant exposure potential, such as healthcare and insurance firms, to maximize both financial and reputational damage. Notable past operations include the attack on Shirbit, which resulted in the theft of sensitive medical records used for extortion purposes. This indicates a strategic shift towards blending traditional cybercrime goals with geopolitical objectives.

IOC Patterns

  • Spear-phishing emails targeting specific sectors
  • Use of encrypted communication channels for C2
  • Exfiltration of large volumes of structured data
  • Ransomware deployment following data theft

Recommended Actions

  • Monitor network traffic for signs of lateral movement and credential dumping.
  • Implement robust DLP solutions to detect unauthorized data exfiltration.
  • Conduct regular employee training on phishing awareness and geopolitical threat vectors.
  • Enhance incident response plans to address potential extortion demands post-breach.
  • Segment critical systems, particularly in the healthcare and insurance sectors.

Suggested Tags

APT
Hack-and-leak
Ransomware
Geopolitical espionage
Critical infrastructure

Confidence Assessment

The information available on BlackShadow is limited to a single campaign in December 2021, making it challenging to fully understand their capabilities and long-term goals. While the group appears sophisticated, particularly given their focus on sensitive sectors and use of extortion tactics, there are gaps in details about their specific tools, techniques, and potential alliances with other threat groups.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Filename 6 Domain 14

References

  1. attack.mitre.org — Cited by web research for: Sandworm Team
  2. docs.rapid7.com — Cited by web research for: Unit 61398
  3. unit42.paloaltonetworks.com — Cited by web research for: BlackCat
  4. www.inss.org.il — Cited by web research for: doxing
  5. www.sentinelone.com — Cited by web research for: Global
  6. learn.microsoft.com — Cited by web research for: Lynx

Intel Summary

14

Techniques

48

Tools

0

Campaigns

37

IOCs

0

Observed Data

5

Tactics

Tags

APT
Hack-and-leak
Ransomware
Geopolitical espionage
Critical infrastructure

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Country of Origin
China (CN)
Confidence
80%
First Seen
Dec 18, 2021
Last Seen
Dec 18, 2021
Added
Jul 21, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.