blackshadow
1 incidentes
1 paises
1 sectores
ransomware IR Ultimo: 2026-06-25
Aliases: Agrius
Black Shadow is a politically motivated cyber-espionage and extortion group assessed with high confidence to be linked to Iranian government interests, specifically attributed to Iran's Ministry of Intelligence and Security. The group emerged with observable activity dating back to early 2019, gaining public notoriety in late 2020 through a series of high-profile attacks against Israeli entities. Unlike typical financially motivated ransomware operations, Black Shadow often employs a hybrid motivation, combining financial extortion with information operations aimed at disruption and public shaming, particularly targeting Israeli citizens and organizations. A defining characteristic of the group is its strategic use of media exploitation, leveraging Telegram channels and news outlets to publicize breaches, leak sensitive data, and exert pressure on victims and their governments, often magnifying the perceived impact of their cyberattacks.
RansomLook pivots
Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.
Abrir perfil →
Paises objetivo (SOCRadar)
United Arab Emirates
Germany
Israel
Lebanon
Russian Federation
Saudi Arabia
Turkey
United States
Sectores atacados
Medical (1)
Sectores objetivo (SOCRadar)
Other Information ServicesRail TransportationSoftware PublishersAccommodationManufacturingPublic AdministrationEducational ServicesWholesale TradeData Processing ServicesInternet Publishing
URLs nuevas detectadas en IntelTracker