Blacktor is a low-profile data breach and extortion group active around 2021 with a Tor-based leak site, claiming victims in Indonesia, Italy, Venezuela, and the US, with minimal public threat-intelligence coverage. Known victims: 4
Objectives
Executive Summary
Blacktor is a low-profile cyber threat actor specializing in data breaches and extortion, operating around 2021. Known for using a Tor-based leak site to blackmail victims into paying ransoms or facing public exposure of stolen data, Blacktor has targeted individuals and organizations across Indonesia, Italy, Venezuela, and the United States. Despite their limited public exposure, they demonstrate medium sophistication in executing their extortion campaigns.
Goals & Targeting
Blacktor's primary motivation appears to be financial gain, as evidenced by their use of extortion and ransomware tactics. Their targeting profile suggests a focus on individuals and organizations that may be more susceptible to such threats due to potential vulnerabilities or lesser defenses. The selection of victims across different countries hints at a broad geographic strategy rather than concentrating on specific industries or regions.
Enhanced Description
Blacktor is a cybercriminal group active during 2021, primarily known for its use of a Tor-based website to facilitate data breaches and extortion activities. The group targeted victims across various countries, including Indonesia, Italy, Venezuela, and the United States, indicating a geographically diverse approach to victim selection without a clear sector-specific focus. Their operational model involves compromising systems through unspecified means, extracting sensitive data, and then threatening to release this information unless a ransom is paid. Blacktor's low-profile nature suggests either effective tradecraft or limited operational ambition, though their choice of methods aligns with common ransomware/extortion tactics observed in the cybercrime landscape.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Blacktor's campaigns appear to be limited in scope, with known activity concentrated around late 2021. Their victims include individuals and small- to medium-sized organizations across diverse geographies, suggesting a focus on easy prey rather than high-value targets. Despite their activities being documented minimally, their use of Tor-based extortion sites and data leakage tactics aligns with prominent cybercrime trends.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in Blacktor's profile is moderate, given the limited available intelligence from 2021. Key gaps include their exact TTPs, specific malware tools, and long-term campaign patterns beyond late 2021.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics