BlackOasis is an advanced persistent threat group associated with cyber-espionage activity and widely tracked under the same name. The group has been linked to targeted exploitation of client-side vulnerabilities, including in-the-wild use of Microsoft Office and Adobe Flash exploit chains, and has been assessed as a user of commercial surveillance tooling including FinSpy. Reported operations indicate a focus on carefully selected victims rather than broad opportunistic campaigns. BlackOasis has been observed using spearphishing and exploit-based initial access, followed by staged shellcode and payload delivery. Its tradecraft includes obfuscated first-stage shellcode and other defensive-evasion measures intended to hinder antivirus detection and analysis. The group is associated with exploitation activity involving CVE-2017-0199 and was publicly identified as an early user of the Adobe Flash vulnerability CVE-2017-11292. Available reporting places BlackOasis within the Middle Eastern threat landscape and characterizes it as an espionage-oriented actor targeting regional and foreign interests, including government-related entities and other strategic victims. Known aliases are limited in the supplied facts, and no distinct sub-groups are directly supported at high confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
5 CVEs this actor has used in observed campaigns. 5 of them exploited in the wild.
We have previously reported on BlackOasis using other zero-days in the past; CVE-2016-4117 in May 2016, CVE-2016-0984 in June 2015, and CVE-2015-5119 in June 2015.
We have previously reported on BlackOasis using other zero-days in the past; CVE-2016-4117 in May 2016, CVE-2016-0984 in June 2015, and CVE-2015-5119 in June 2015.
We have previously reported on BlackOasis using other zero-days in the past; CVE-2016-4117 in May 2016, CVE-2016-0984 in June 2015, and CVE-2015-5119 in June 2015.
we did produce two reports revolving around the use of a zero-day exploit (CVE-2017-0199). The most notable involved an actor we refer to as BlackOasis and their usage of the exploit in-the-wild prior to its discovery.
Proofpoint researchers detected a malicious Microsoft Word attachment exploiting a recently patched Adobe Flash vulnerability, CVE-2017-11292... DealersChoice.B ... is now also exploiting CVE-2017-11292, a Flash vulnerability that can lead to arbitrary code execution across Windows, Mac OS, Linux, and Chrome OS systems.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as an associated threat actor in the detection annotations for exploitation-related activity.
Listed as a threat actor associated with the Linux base64-to-shell execution detection analytic.
Listed as a threat actor associated with the Obfuscated Files or Information (T1027) defense evasion technique, specifically relevant to base64 decoding on Linux.
Referenced as a threat actor associated with use of obfuscated PowerShell encoded commands for defense evasion.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.