Black Mirror is a hacker group active since at least 2019 that has marketed alleged stolen data associated with prominent figures connected to the Russian state. The group has publicly claimed responsibility for compromising accounts used by Russian journalist and media executive Ksenia Sobchak, briefly taking control of several of her Telegram channels after gaining access through her email account, according to the victim. Black Mirror then used the hijacked channels to publish purported excerpts from private correspondence and claimed to possess a large archive of Sobchak-related data, which it offered for sale. The authenticity of the leaked material and the group’s claims about the archive have not been independently verified. Black Mirror has also previously offered purported archives attributed to other high-profile Russian figures, including Sergei Shoigu and Yevgeny Prigozhin. Based on the verified reporting available here, the group’s observed behavior centers on unauthorized account access, theft or claimed theft of private communications, publication of selected materials, and monetization of allegedly stolen data. Its activity is consistent with credential compromise, account takeover, exfiltration, and financially motivated sale of stolen information, but broader attribution, organizational structure, and state affiliation are not established at high confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.