BlackOasis
BlackOasis is an advanced threat group referenced as distinct from APT28. Kaspersky attributed in-the-wild exploitation of Adobe Flash vulnerability CVE-2017-11292 to BlackOasis, and Kaspersky’s Q2 2017 APT reporting also described BlackOasis as a Middle Eastern actor exploiting CVE-2017-0199. The content states that BlackOasis was believed to be a customer of Gamma Group and to use FinSpy. Reported tradecraft includes exploitation of client-side vulnerabilities and defense-evasion through obfuscation: BlackOasis first-stage shellcode contained a NOP sled with alternative instructions that was likely designed to bypass antivirus tools. The content also associates BlackOasis with MITRE ATT&CK technique T1027 (Obfuscated Files or Information) and with base64 decoding and encoded-command style obfuscation behaviors in analytic mappings. Known alias in the provided content: blackoasis.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
1 malware family attributed to this actor across reporting.
Associated vulnerabilities
5 CVEs this actor has used in observed campaigns. 5 of them exploited in the wild.
We have previously reported on BlackOasis using other zero-days in the past; CVE-2016-4117 in May 2016, CVE-2016-0984 in June 2015, and CVE-2015-5119 in June 2015.
We have previously reported on BlackOasis using other zero-days in the past; CVE-2016-4117 in May 2016, CVE-2016-0984 in June 2015, and CVE-2015-5119 in June 2015.
We have previously reported on BlackOasis using other zero-days in the past; CVE-2016-4117 in May 2016, CVE-2016-0984 in June 2015, and CVE-2015-5119 in June 2015.
we did produce two reports revolving around the use of a zero-day exploit (CVE-2017-0199). The most notable involved an actor we refer to as BlackOasis and their usage of the exploit in-the-wild prior to its discovery.
Proofpoint researchers detected a malicious Microsoft Word attachment exploiting a recently patched Adobe Flash vulnerability, CVE-2017-11292... DealersChoice.B ... is now also exploiting CVE-2017-11292, a Flash vulnerability that can lead to arbitrary code execution across Windows, Mac OS, Linux, and Chrome OS systems.
Recent activity
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as an associated threat actor in the detection annotations for exploitation-related activity.
Listed as a threat actor associated with the Linux base64-to-shell execution detection analytic.
Listed as a threat actor associated with the Obfuscated Files or Information (T1027) defense evasion technique, specifically relevant to base64 decoding on Linux.
Referenced as a threat actor associated with use of obfuscated PowerShell encoded commands for defense evasion.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.