BlackJack is a hacktivist threat group associated with destructive and disruptive intrusions targeting Russian organizations. Reporting places it within a broader ecosystem of anti-Russia clusters active since the Russo-Ukrainian war, alongside groups such as Twelve, Head Mare, C.A.S, and Crypt Ghouls. BlackJack has been linked through tooling and tradecraft overlaps to campaigns against Russian government, telecom, industrial, and other enterprise targets. The group is notable for overlap with other Russia-targeting actors rather than for a fully distinct, independently documented toolchain. Shared elements reported across related activity include credential-harvesting utilities, remote administration and tunneling tools, reconnaissance software, proxying utilities, and destructive payload deployment. BlackJack has been associated with the use of XenAllPasswordPro and with overlaps involving CobInt-related tooling, resocks, SoftPerfect Network Scanner, and DLL sideloading patterns also seen in Crypt Ghouls activity. Kaspersky also identified overlaps between BlackJack and Twelve, including destructive operations involving ransomware and wiper components. BlackJack has been publicly connected to attacks claimed against Russian municipal or state-linked entities, including operations involving the Fuxnet wiper. Related reporting indicates use of destructive malware families such as Shamoon and LockBit in the surrounding cluster of activity. The group is generally characterized as hacktivist rather than financially motivated, with operations aimed at disruption, sabotage, and public impact. Available information does not support a high-confidence standalone attribution to a specific state, but BlackJack is consistently described as part of the pro-Ukrainian or anti-Russian hacktivist landscape. Aliases are limited in the available reporting; BlackJack is the primary name in use. Its significance lies in its participation in a loosely connected set of actors sharing tools, infrastructure patterns, and operational knowledge while targeting Russian organizations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Hacktivist group active against Russian organizations, motivated by disruption and public pressure.
Group noted here for toolkit overlap with Crypt Ghouls, specifically use of XenAllPasswordPro.
Referenced as a related ransomware intrusion cluster sharing utilities and potentially infrastructure with Crypt Ghouls, complicating attribution.
Referenced as a separate group conducting similar recent campaigns targeting Russia with overlapping tools/infrastructure; no additional details provided in the content.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.