The BlackMagic ransomware group targeted transportation and logistics organizations in Israel, publicly naming more than ten victims and claiming to have stolen roughly 50GB of data. Researchers said the operation combined encryption with double extortion, but unlike typical ransomware campaigns, the group reportedly omitted payment instructions from its ransom note and instead advertised stolen data on social media and cybercrime forums. The leaked material was described as sensitive transportation-sector information that could affect more than 65% of Israeli citizens, and investigators said the campaign showed signs of both disruptive and financially motivated activity.
Technical analysis found BlackMagic used malware aligned with MITRE ATT&CK T1486 (Data Encrypted for Impact). The payload was a 64-bit DLL launched through rundll32.exe, used repeated sleep calls to evade sandboxing, terminated numerous processes, disabled Task Manager, contacted 5.230.70.49, encrypted files with the Rijndael algorithm, and appended the .BlackMagic extension. It also dropped a batch file to change the desktop wallpaper, force a reboot, and remove traces, while researchers noted similarities to earlier anti-Israel disruptive ransomware activity, including Moses Staff.

TTPs, infrastructure, and targeting history in one profile.
2 events from the most recent confirmed update back to the earliest known activity.
During a threat-hunting exercise, Cyble Research and Intelligence Labs identified a ransomware group named BlackMagic and published technical analysis of its malware, infrastructure, and tactics. The report assessed that the activity may be politically motivated, possibly linked to Iran, while also showing signs of financial motivation through attempted data sales.
Cyble reported that the BlackMagic ransomware group targeted organizations in Israel's transportation and logistics sector, using double extortion and disruptive actions such as database destruction, altered lading bills, and website defacements. The group publicly disclosed more than ten Israeli victims and claimed to have stolen about 50GB of data affecting over 65% of Israeli citizens.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 9 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.