Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors blacktor

Description

Blacktor is a low-profile data breach and extortion group active around 2021 with a Tor-based leak site, claiming victims in Indonesia, Italy, Venezuela, and the US, with minimal public threat-intelligence coverage. Known victims: 4

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

Blacktor is a low-profile cyber threat actor specializing in data breaches and extortion, operating around 2021. Known for using a Tor-based leak site to blackmail victims into paying ransoms or facing public exposure of stolen data, Blacktor has targeted individuals and organizations across Indonesia, Italy, Venezuela, and the United States. Despite their limited public exposure, they demonstrate medium sophistication in executing their extortion campaigns.

Goals & Targeting

Blacktor's primary motivation appears to be financial gain, as evidenced by their use of extortion and ransomware tactics. Their targeting profile suggests a focus on individuals and organizations that may be more susceptible to such threats due to potential vulnerabilities or lesser defenses. The selection of victims across different countries hints at a broad geographic strategy rather than concentrating on specific industries or regions.

Enhanced Description

Blacktor is a cybercriminal group active during 2021, primarily known for its use of a Tor-based website to facilitate data breaches and extortion activities. The group targeted victims across various countries, including Indonesia, Italy, Venezuela, and the United States, indicating a geographically diverse approach to victim selection without a clear sector-specific focus. Their operational model involves compromising systems through unspecified means, extracting sensitive data, and then threatening to release this information unless a ransom is paid. Blacktor's low-profile nature suggests either effective tradecraft or limited operational ambition, though their choice of methods aligns with common ransomware/extortion tactics observed in the cybercrime landscape.

Key Capabilities

  • Data breach
  • Extortion through Tor sites
  • Ransomware deployment
  • Phishing

MITRE ATT&CK Tactics

Exfiltration of Data
Extortion
Resilience

ATT&CK Techniques

T1036
T1057
T1048
T1022

Software / Tooling

Custom Ransomware
Phishing Tools

Campaigns & Victims

Blacktor's campaigns appear to be limited in scope, with known activity concentrated around late 2021. Their victims include individuals and small- to medium-sized organizations across diverse geographies, suggesting a focus on easy prey rather than high-value targets. Despite their activities being documented minimally, their use of Tor-based extortion sites and data leakage tactics aligns with prominent cybercrime trends.

IOC Patterns

  • Anomalous Tor network activity
  • Phishing emails mimicking legitimate services
  • Encrypted files related to known ransomware strains

Recommended Actions

  • Implement robust email filtering and anti-phishing solutions
  • Monitor for unusual network traffic indicative of data exfiltration
  • Encrypt sensitive data at rest and in transit
  • Conduct regular employee training on phishing and social engineering tactics

Suggested Tags

Organized Crime
Ransomware
Extortion
Tor
Multi-Regional

Confidence Assessment

Confidence in Blacktor's profile is moderate, given the limited available intelligence from 2021. Key gaps include their exact TTPs, specific malware tools, and long-term campaign patterns beyond late 2021.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Data Exfiltration
Organized Crime
Ransomware
Extortion
Tor
Multi-Regional

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Dec 30, 2021
Last Seen
Dec 30, 2021
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.