Actor Profile

🏹 blackshadow — Ransomware

BlackShadow is an Iranian-linked hack-and-leak group (linked to the Agrius APT) that targeted Israeli companies including insurance firm Shirbit and hosting provider Cyberserve, leaking medical records of 290,000 patients, using extortion as a tool of geopolitical disruption rather than purely for financial gain.
🔄 Pivot:🏹 blackshadow

Classification

Ransomware

Leak-site victims

3
Ransomware.live

Associated IoCs

0
local intel

MITRE techniques

ATT&CK

Tracked

Yes
Ransomware.live

🔥 Leak-Site Victims (3)

VictimCountryPublishedDomain
Shirbit Insurance Company 2021-12-18T16:06:44.948812+00:00
K.L.S Capital 2021-12-18T16:06:44.925671+00:00
CyberServe Company 2021-12-18T16:06:44.900296+00:00

Source: Ransomware.live leak-site monitoring (cached, offline-safe).

🧭 Intelligence disciplines

CYBINT →OSINT →HUMINT →GEOINT →
Live group profile & victims via Ransomware.live; ATT&CK technique hints are a static reference for well-known groups. All network calls cached & offline-safe.
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php