Also known as: Sandworm Team, tracked as, Black Shadow, a dark fleet, is a ship, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, APT28, VOLTZITE, for follow-on operations, Unit 61398, BlackCat, Gookee, kapuchin0, Guki, leaked the source code, shut the operation down, doxing, doxfare, hack, Tech Sectors, November 6, 2023, Marc Salinas Fernandez, Jiri Vinopal, Royal Ransomware, Agrius
BlackShadow is an Iranian-linked hack-and-leak group (linked to the Agrius APT) that targeted Israeli companies including insurance firm Shirbit and hosting provider Cyberserve, leaking medical records of 290,000 patients, using extortion as a tool of geopolitical disruption rather than purely for financial gain. Known victims: 3
Objectives
Targeted Sectors
Targeted Countries / Regions
Executive Summary
BlackShadow, a medium-sophistication Iranian-linked hack-and-leak group with ties to the Agrius APT, has emerged as a notable threat actor targeting Israeli organizations. In December 2021, they attacked insurance firm Shirbit and hosting provider Cyberserve, compromising medical records of over 290,000 patients. Unlike typical cybercriminals, BlackShadow's primary motivation appears to be geopolitical disruption through extortion and data leaks, blending financial gain with strategic objectives.
Goals & Targeting
BlackShadow's strategic objectives appear to be twofold: achieving financial gain through ransom demands and causing geopolitical disruption by targeting Israeli entities. Their choice of victims, including insurance firms and hosting providers, indicates a focus on sectors with high exposure to sensitive data that can be weaponized for both monetary and reputational damage. The group's activities are likely intended to exert pressure on Israel's critical infrastructure while demonstrating technical expertise in infiltratingand compromising such targets.
Enhanced Description
BlackShadow is an Iranian-linked cyber threat group known for its hack-and-leak operations, particularly targeting Israeli companies. The group has been associated with the Agrius APT and has demonstrated a focus on critical sectors such as insurance and hosting services. In one notable operation, they targeted Shirbit, an Israeli insurance firm, and Cyberserve, a major hosting provider, resulting in the exposure of sensitive medical records of over 290,000 individuals. This attack highlights BlackShadow's ability to disrupt both financial and healthcare sectors while leveraging data as a tool for extortion and geopolitical pressure. The group's activities suggest a sophisticated operational capacity, likely involving advanced persistent threats (APTs), and their modus operandi includes the use of extortion tactics and data dumping to achieve strategic objectives rather than purely financially motivated ransomware campaigns.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
BlackShadow's campaign in December 2021 demonstrated a rapid operational tempo, targeting multiple high-value organizations within the same timeframe. The group appears to focus on victims with significant exposure potential, such as healthcare and insurance firms, to maximize both financial and reputational damage. Notable past operations include the attack on Shirbit, which resulted in the theft of sensitive medical records used for extortion purposes. This indicates a strategic shift towards blending traditional cybercrime goals with geopolitical objectives.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The information available on BlackShadow is limited to a single campaign in December 2021, making it challenging to fully understand their capabilities and long-term goals. While the group appears sophisticated, particularly given their focus on sensitive sectors and use of extortion tactics, there are gaps in details about their specific tools, techniques, and potential alliances with other threat groups.
No campaigns linked yet.
No observed data linked yet.
14
Techniques
48
Tools
0
Campaigns
37
IOCs
0
Observed Data
5
Tactics