Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors BlackOasis

Also known as: G0063

Description

BlackOasis is a Middle Eastern threat group that is believed to be a customer of Gamma Group. The group has shown interest in prominent figures in the United Nations, as well as opposition bloggers, activists, regional news correspondents, and think tanks. (Citation: Securelist BlackOasis Oct 2017) (Citation: Securelist APT Trends Q2 2017) A group known by Microsoft as NEODYMIUM is reportedly associated closely with BlackOasis operations, but evidence that the group names are aliases has not been identified. (Citation: CyberScoop BlackOasis Oct 2017)

Goals & Targeting

Targeted Sectors

Ngo

Targeted Countries / Regions

RU
GB
IR
SA

AI Analysis

· 1 week ago

Executive Summary

BlackOasis is a Middle Eastern threat group linked to Gamma Group, targeting NGOs, media organizations, and prominent figures for espionage. Their operations focus on data collection and influence activities, particularly in regions with high political tensions.

Goals & Targeting

BlackOasis aims for espionage, targeting sectors like NGOs and media in countries such as Russia, UK, Iran, and Saudi Arabia. The targeting of politically active individuals suggests a desire to influence regional dynamics by gathering sensitive information.

Enhanced Description

BlackOasis operates primarily in the Middle East, targeting NGOs, UN officials, activists, bloggers, news correspondents, and think tanks. They are associated with Gamma Group, known for selling spyware, but no confirmed aliases exist between BlackOasis and Microsoft's NEODYMIUM group. Their activities involve espionage to gather intelligence on opposition groups.

Key Capabilities

  • Espionage using Gamma Group tools
  • Phishing attacks
  • Malware deployment

MITRE ATT&CK Tactics

Espionage

ATT&CK Techniques

T1027

Campaigns & Victims

BlackOasis likely engages in long-term operations targeting sensitive regions, using APT tactics to infiltrate and exfiltrate data from targeted organizations.

IOC Patterns

  • Spear-phishing emails
  • Obfuscated files

Recommended Actions

  • Enhance email filtering
  • Monitor for Gamma Group tools
  • Conduct regular threat hunting

Suggested Tags

APT
espionage

Confidence Assessment

Moderate confidence, as details on specific TTPs beyond Gamma Group links are limited.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. Securelist BlackOasis Oct 2017 — Kaspersky Lab's Global Research & Analysis Team. (2017, October 16). BlackOasis APT and new targeted attacks leveraging zero-day exploit. Retrieved February 15, 2018.
  2. Securelist APT Trends Q2 2017 — Kaspersky Lab's Global Research & Analysis Team. (2017, August 8). APT Trends report Q2 2017. Retrieved February 15, 2018.
  3. CyberScoop BlackOasis Oct 2017 — Bing, C. (2017, October 16). Middle Eastern hacking group is using FinFisher malware to conduct international espionage. Retrieved February 15, 2018.

Intel Summary

1

Techniques

6

Tools

0

Campaigns

0

IOCs

0

Observed Data

1

Tactics

Tags

APT
Critical Infrastructure
espionage

Details

MITRE ID
G0063
Type
Unknown
Resource Level
Unknown
Primary Motivation
Espionage
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--da49b9f1-ca99-443f-9728-0a074db66850
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.