BlackOasis is an advanced persistent threat group associated with cyber-espionage activity and widely tracked under the same name. The group has been linked to targeted exploitation of client-side vulnerabilities, including in-the-wild use of Microsoft Office and Adobe Flash exploit chains, and has been assessed as a user of commercial surveillance tooling including FinSpy. Reported operations indicate a focus on carefully selected victims rather than broad opportunistic campaigns. BlackOasis has been observed using spearphishing and exploit-based initial access, followed by staged shellcode and payload delivery. Its tradecraft includes obfuscated first-stage shellcode and other defensive-evasion measures intended to hinder antivirus detection and analysis. The group is associated with exploitation activity involving CVE-2017-0199 and was publicly identified as an early user of the Adobe Flash vulnerability CVE-2017-11292. Available reporting places BlackOasis within the Middle Eastern threat landscape and characterizes it as an espionage-oriented actor targeting regional and foreign interests, including government-related entities and other strategic victims. Known aliases are limited in the supplied facts, and no distinct sub-groups are directly supported at high confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
5 CVEs this actor has used in observed campaigns. 5 of them exploited in the wild.
We have previously reported on BlackOasis using other zero-days in the past; CVE-2016-4117 in May 2016, CVE-2016-0984 in June 2015, and CVE-2015-5119 in June 2015.
We have previously reported on BlackOasis using other zero-days in the past; CVE-2016-4117 in May 2016, CVE-2016-0984 in June 2015, and CVE-2015-5119 in June 2015.
We have previously reported on BlackOasis using other zero-days in the past; CVE-2016-4117 in May 2016, CVE-2016-0984 in June 2015, and CVE-2015-5119 in June 2015.
we did produce two reports revolving around the use of a zero-day exploit (CVE-2017-0199). The most notable involved an actor we refer to as BlackOasis and their usage of the exploit in-the-wild prior to its discovery.
Proofpoint researchers detected a malicious Microsoft Word attachment exploiting a recently patched Adobe Flash vulnerability, CVE-2017-11292... DealersChoice.B ... is now also exploiting CVE-2017-11292, a Flash vulnerability that can lead to arbitrary code execution across Windows, Mac OS, Linux, and Chrome OS systems.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as an associated threat actor in the detection annotations for exploitation-related activity.
Listed as a threat actor associated with the Linux base64-to-shell execution detection analytic.
Listed as a threat actor associated with the Obfuscated Files or Information (T1027) defense evasion technique, specifically relevant to base64 decoding on Linux.
Referenced as a threat actor associated with use of obfuscated PowerShell encoded commands for defense evasion.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.