Blackshades is a Windows-focused remote access trojan that emerged around 2010 and was widely sold on underground forums at low cost, contributing to large-scale global abuse. It enabled remote control of infected systems and was used to compromise and spy on hundreds of thousands of computers worldwide. Public reporting and law-enforcement actions have linked its development and sale to Alex Yücel and Michael Hogue.
Blackshades provides attackers with broad remote-administration and surveillance capabilities, including unauthorized access to victim machines, file access and modification, keystroke logging, webcam access, payload download and execution, and use of infected hosts as proxies. It has also been used to direct infected systems into distributed denial-of-service activity and has been described as capable of lock-screen style ransom behavior. Operators commonly paired it with obfuscation tools to reduce antivirus detection.
Distribution has been associated with malicious webpages, including drive-by download activity, as well as removable media such as USB devices. The malware was used both by opportunistic cybercriminals and in politically motivated surveillance. It was documented in campaigns targeting Syrian opposition figures, and it also figured in criminal sextortion cases involving covert webcam surveillance and theft of intimate material.
Blackshades became the subject of major international law-enforcement action, culminating in a 2014 coordinated crackdown spanning numerous countries and resulting in arrests, searches, and device seizures. Its history is frequently cited as a prominent example of a commodity RAT marketed as a purported administration tool but broadly used for unauthorized access, surveillance, and other criminal activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ALUMINUM SARATOGA ... Tools ... BlackShades, BrittleBush, DarkComet, LastConn, Micropsia, NimbleMamba, PoisonIvy, QuasarRAT, XtremeRat
16 distinct techniques documented for this family, organized by ATT&CK tactic.
The attacks we have documented usually involve the use of malicious links or e-mail attachments, designed to obtain information from a device.
We found that the spyware has a modular design, and can download additional modules from a command & control (C&C) server, including password capture...
We found that the spyware has a modular design, and can download additional modules from a command & control (C&C) server, including password capture (from over 20 applications) and recording of screenshots...
"...or through external storage devices, such as USB flash drives."
The attacks often include fake or maliciously packaged security tools; intriguing, or ideological, or movement-relevant content... Researchers and security professionals have already profiled many of these RATs, including DarkComet, Blackshades Remote Controller, Xtreme RAT, njRAT, and ShadowTech.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as a tool used by the ALUMINUM SARATOGA threat profile.
Remote Access Trojan (RAT) used by Molerats for espionage and surveillance.
A remote access trojan used to compromise and spy on large numbers of computers; referenced here because the alleged owner of RevCode/WebMonitor shares the same identity as a convicted Blackshades co-creator.
A cheap and powerful Remote Access Trojan reportedly used to infect more than half a million computers worldwide.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.