BlackJack is a pro-Ukrainian hacktivist cluster assessed in some reporting as allegedly state-sponsored by Ukraine. The group is known for targeting Russian organizations, including government, telecommunications, and industrial control system environments, with an emphasis on disruptive and destructive operations rather than conventional financially motivated crime. BlackJack has been publicly associated with the destructive FuxNet malware used against Moskollektor, an organization involved in monitoring Moscow water and sewage sensor networks. Reported tradecraft in that campaign included initial access via exposed cellular routers, tunneling into internal enterprise systems, and deployment of FuxNet over SSH or proprietary sensor-management channels to large numbers of field devices and gateways. FuxNet was described as locking out remote access, shutting down communications, wiping filesystems, writing to block devices, and attempting flash wear-out to brick targeted devices. BlackJack has also been reported using legitimate remote administration and tunneling tools for persistence and remote operations, including AnyDesk, Radmin, PuTTY, and ngrok, across Russian government, telecom, and ICS targets. Multiple analyses place BlackJack within a broader ecosystem of Russia-targeting hacktivist or hybrid clusters that includes Twelve, MorLock, Crypt Ghouls, and Shedding Zmiy/ExCobalt, citing overlaps in tooling and operational artifacts such as XenAllPasswordPro, CobInt-related components, resocks, SoftPerfect Network Scanner, and DLL sideloading patterns. These overlaps suggest shared tooling, collaboration, or partial operator overlap, but do not by themselves establish full identity between the groups. BlackJack has been linked to destructive malware use, including FuxNet, and some reporting also notes overlap with campaigns involving LockBit 3.0 and Shamoon-style wiping activity. The actor is best characterized as a Russia-focused disruptive threat group operating in the context of the Russo-Ukrainian conflict, with demonstrated capability against both enterprise and OT-adjacent infrastructure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a threat actor that used AnyDesk and other remote administration/tunneling tools for persistence.
Hacktivist group active against Russian organizations, motivated by disruption and public pressure.
Group noted here for toolkit overlap with Crypt Ghouls, specifically use of XenAllPasswordPro.
Conducted a destructive attack against Russian water and sewage monitoring infrastructure using FuxNet to brick Linux-based cellular routers and gateways after gaining access through exposed cellular routers and tunneling into internal enterprise systems.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.