ATT&CKGroupsBlackOasis

BlackOasis

G0063

Threat group.View on attack.mitre.org

About this group

BlackOasis is a Middle Eastern threat group that is believed to be a customer of Gamma Group. The group has shown interest in prominent figures in the United Nations, as well as opposition bloggers, activists, regional news correspondents, and think tanks. A group known by Microsoft as NEODYMIUM is reportedly associated closely with BlackOasis operations, but evidence that the group names are aliases has not been identified.

Techniques used1

Procedure examples1

TechniqueProcedure example
T1027
Obfuscated Files or Information

BlackOasis's first stage shellcode contains a NOP sled with alternative instructions that was likely designed to bypass antivirus tools.

Software0

None recorded.

Campaigns0

None recorded.

References3

  1. CyberScoop BlackOasis Oct 2017 Open source
    Bing, C. (2017, October 16). Middle Eastern hacking group is using FinFisher malware to conduct international espionage. Retrieved February 15, 2018.
  2. Securelist APT Trends Q2 2017 Open source
    Kaspersky Lab's Global Research & Analysis Team. (2017, August 8). APT Trends report Q2 2017. Retrieved February 15, 2018.
  3. Securelist BlackOasis Oct 2017 Open source
    Kaspersky Lab's Global Research & Analysis Team. (2017, October 16). BlackOasis APT and new targeted attacks leveraging zero-day exploit. Retrieved February 15, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.