Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Enjoying ransomware.live? Help us keep tracking ransomware gangs and shipping new features. Support us

Blackshadow

BlackShadow is an Iranian-linked hack-and-leak group (linked to the Agrius APT) that targeted Israeli companies including insurance firm Shirbit and hosting provider Cyberserve, leaking medical records of 290,000 patients, using extortion as a tool of geopolitical disruption rather than purely for financial gain.

Victims
3
 
First Discovered
2021-12-18
victim
Last Discovered
2021-12-18
victim
Inactive Since
4yrs
more than
Avg Delay
N/A
attack→claim
Infostealer
N/A
victims with domain
Countries
0
hit
View Victims on World Map View Group Statistics

Known Locations (1)
Favicon Title Type Available Last Visit Server Info FQDN
favicon No 2026-05-27T10:44:22 544corkfh5hwhtn4.onion

Target
Top 5 Activity Sectors
  • Financial Services 2
  • Technology 1
Top 5 Countries

Heatmap

TTPs Matrix (12)
This information is provided by Crocodyli & Ransomware.live
Initial Access Execution Persistence Privilege Escalation Stealth Credential Access Discovery Lateral Movement Collection Exfiltration Resource Development Defense Impairment
Valid Accounts: Domain Accounts Command and Scripting Interpreter: Windows Command Shell Valid Accounts: Domain Accounts Valid Accounts: Domain Accounts Masquerading OS Credential Dumping: LSASS Memory Remote System Discovery Remote Services: Remote Desktop Protocol Data from Local System Exfiltration Over C2 Channel Acquire Infrastructure Disable or Modify Tools
Exploit Public-Facing Application   Server Software Component: Web Shell Create or Modify System Process: Windows Service Valid Accounts: Domain Accounts OS Credential Dumping: Security Account Manager Network Service Discovery Lateral Tool Transfer Data Staged: Local Data Staging      
    Create or Modify System Process: Windows Service   Deobfuscate/Decode Files or Information Brute Force     Automated Collection      
          Brute Force: Password Spraying     Archive Collected Data: Archive via Utility      

YARA Rules (1)

Victims (3)
Logo
Discovered: 2021-12-18 (4y ago)
No description available
Logo
Discovered: 2021-12-18 (4y ago)
No description available
Logo
Discovered: 2021-12-18 (4y ago)
No description available