BlackJack
BlackJack is a hacktivist threat group targeting Russian entities, including industrial and critical infrastructure. Kaspersky reported overlaps between BlackJack and the previously known group Twelve, and assessed that BlackJack is part of a broader set of Russia-targeting clusters that also includes MorLock and Shedding Zmiy (ExCobalt), with shared tooling, procedures, and infrastructure complicating attribution. Kaspersky specifically identified overlaps between Twelve and BlackJack, and noted that BlackJack also used Shamoon and LockBit in attacks. BlackJack claimed responsibility for the “MOSCOLLECTOR TAKEDOWN” attack against moscollector.ru, described as Russia’s industrial sensor and monitoring infrastructure. According to the provided reporting, the operation allegedly disabled 87,000 sensors across Russian critical infrastructure, including emergency services and utilities. In that attack, BlackJack used the custom ICS/OT malware Fuxnet to manipulate and destroy OT systems and technology. Dragos likewise reported that BlackJack used custom ICS malware Fuxnet to disable 87,000 sensors in Russian critical infrastructure. Kaspersky stated that its report detailed the tools, malware, and procedures of the BlackJack group and linked it to Twelve. The content directly mentions BlackJack as a hacktivist group and ties it to destructive operations against Russian targets, with observed overlap in tooling and tradecraft with Twelve.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- government
- telecommunications
- industrial
Tradecraft
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
Recent activity
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Hacktivist cluster targeting Russia; linked to Twelve; associated with wiper and ransomware tooling (some samples not definitively attributable).
Referenced as a related ransomware intrusion cluster sharing utilities and potentially infrastructure with Crypt Ghouls, complicating attribution.
Referenced as a separate group conducting similar recent campaigns targeting Russia with overlapping tools/infrastructure; no additional details provided in the content.
Hacktivist/destructive actor overlapping with Twelve; claimed attacks on Russian targets (e.g., Moscollector) using wipers (Fuxnet; also Shamoon) and LockBit, with stated non-financial motive to maximize damage (encrypt/delete/steal).
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.