🏹 blackshadow — Ransomware
BlackShadow is an Iranian-linked hack-and-leak group (linked to the Agrius APT) that targeted Israeli companies including insurance firm Shirbit and hosting provider Cyberserve, leaking medical records of 290,000 patients, using extortion as a tool of geopolitical disruption rather than purely for financial gain.
🔄 Pivot:🏹 blackshadow
Classification
Ransomware
Leak-site victims
3
Ransomware.live
Associated IoCs
0
local intel
MITRE techniques
—
ATT&CK
Tracked
Yes
Ransomware.live
🔥 Leak-Site Victims (3)
| Victim | Country | Published | Domain |
|---|---|---|---|
| Shirbit Insurance Company | 2021-12-18T16:06:44.948812+00:00 | — | |
| K.L.S Capital | 2021-12-18T16:06:44.925671+00:00 | — | |
| CyberServe Company | 2021-12-18T16:06:44.900296+00:00 | — |
Source: Ransomware.live leak-site monitoring (cached, offline-safe).
🏹 Campaigns & malware
🧩 Advanced Capabilities
Live group profile & victims via Ransomware.live; ATT&CK technique hints are a static reference for well-known groups. All network calls cached & offline-safe.
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Explore related tools below
- Automate recurring work via cron