Ransomware Group intelligence
Blackshadow
InactiveTrack Blackshadow with 3 published victims and 1 known leak locations in a single intelligence view.
Overview
Blackshadow is tracked by Breach House as a ransomware group with 3 published victims.
The group is tracked across multiple victim records in the Breach House dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Down checked 25m ago | 544corkfh5hwhtn4.onion |
Top Activity Sectors (3)
Typical Attacks (22)
▼How Blackshadow typically operates, as attributed by MITRE ATT&CK v19.2. Attributed via Agrius.
-
T1583 Acquire Infrastructure Resource Development
What they do: Agrius typically uses commercial VPN services for anonymizing last-hop traffic to victim networks, such as ProtonVPN.
What that means: Adversaries may buy, lease, rent, or obtain infrastructure that can be used during targeting.
-
What they do: Agrius attempted to acquire valid credentials for victim environments through various means to enable follow-on lateral movement.
What that means: Adversaries may obtain and abuse credentials of a domain account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
-
T1190 Exploit Public-Facing Application Initial Access
What they do: Agrius exploits public-facing applications for initial access to victim environments.
What that means: Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
-
T1059.003 Windows Command Shell Execution
What they do: Agrius uses ASPXSpy web shells to enable follow-on command execution via cmd.exe.
What that means: Adversaries may abuse the Windows command shell for execution.
-
T1505.003 Web Shell Persistence
What they do: Agrius typically deploys a variant of the ASPXSpy web shell following initial access via exploitation.
What that means: Adversaries may backdoor web servers with web shells to establish persistent access to systems.
-
What they do: Agrius has deployed IPsec Helper malware post-exploitation and registered it as a service for persistence.
What that means: Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence.
-
T1036 Masquerading Stealth
What they do: Agrius used the Plink tool for tunneling and connections to remote machines, renaming it systems.exe in some instances.
What that means: Adversaries may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools.
-
T1140 Deobfuscate/Decode Files or Information Stealth
What they do: Agrius has deployed base64-encoded variants of ASPXSpy to evade detection.
What that means: Adversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: Agrius used several mechanisms to try to disable security tools.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1003.001 LSASS Memory Credential Access
What they do: Agrius used tools such as Mimikatz to dump LSASS memory to capture credentials in victim environments.
What that means: Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS).
-
T1003.002 Security Account Manager Credential Access
What they do: Agrius dumped the SAM file on victim machines to capture credentials.
What that means: Adversaries may attempt to extract credential material from the Security Account Manager (SAM) database either through in-memory techniques or through the Windows Registry where the SAM database is stored.
-
T1110 Brute Force Credential Access
What they do: Agrius engaged in various brute forcing activities via SMB in victim environments.
What that means: Adversaries may use brute force techniques to gain access to accounts when passwords are unknown or when password hashes are obtained.
-
T1110.003 Password Spraying Credential Access
What they do: Agrius engaged in password spraying via SMB in victim environments.
What that means: Adversaries may use a single or small list of commonly used passwords against many different accounts to attempt to acquire valid account credentials.
-
T1018 Remote System Discovery Discovery
What they do: Agrius used the tool NBTscan to scan for remote, accessible hosts in victim environments.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1046 Network Service Discovery Discovery
What they do: Agrius used the open-source port scanner WinEggDrop to perform detailed scans of hosts of interest in victim networks.
What that means: Adversaries may attempt to get a listing of services running on remote hosts and local network infrastructure devices, including those that may be vulnerable to remote software exploitation.
-
T1021.001 Remote Desktop Protocol Lateral Movement
What they do: Agrius tunnels RDP traffic through deployed web shells to access victim environments via compromised accounts.
What that means: Adversaries may use Valid Accounts to log into a computer using the Remote Desktop Protocol (RDP).
-
T1570 Lateral Tool Transfer Lateral Movement
What they do: Agrius downloaded some payloads for follow-on execution from legitimate filesharing services such as ufile.io and easyupload.io.
What that means: Adversaries may transfer tools or other files between systems in a compromised environment.
-
T1005 Data from Local System Collection
What they do: Agrius gathered data from database and other critical servers in victim environments, then used wiping mechanisms as an anti-analysis and anti-forensics mechanism.
What that means: Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to find files of interest and sensitive data prior to Exfiltration.
-
T1074.001 Local Data Staging Collection
What they do: Agrius has used the folder, C:\\windows\\temp\\s\\, to stage data for exfiltration.
What that means: Adversaries may stage collected data in a central location or directory on the local system prior to Exfiltration.
-
T1119 Automated Collection Collection
What they do: Agrius used a custom tool, sql.net4.exe, to query SQL databases and then identify and extract personally identifiable information.
What that means: Once established within a system or network, an adversary may use automated techniques for collecting internal data.
-
T1560.001 Archive via Utility Collection
What they do: Agrius used 7zip to archive extracted data in preparation for exfiltration.
What that means: Adversaries may use utilities to compress and/or encrypt collected data prior to exfiltration.
-
T1041 Exfiltration Over C2 Channel Exfiltration
What they do: Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers.
What that means: Adversaries may steal data by exfiltrating it over an existing command and control channel.
Victims (3)
Search, filter and paginate the victim timeline for Blackshadow. Showing 1–3 of 3.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Shirbit Insurance Company id2224 View details | Finance / Legal / Insurance | — | ||
|
No additional victim description available. |
|||||
| Ransomware | K.L.S Capital id2223 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | CyberServe Company id2222 View details | IT | — | ||
|
No additional victim description available. |
|||||