Actor Profile

🏹 blacktor — Ransomware

Blacktor is a low-profile data breach and extortion group active around 2021 with a Tor-based leak site, claiming victims in Indonesia, Italy, Venezuela, and the US, with minimal public threat-intelligence coverage.
🔄 Pivot:🏹 blacktor

Classification

Ransomware

Leak-site victims

4
Ransomware.live

Associated IoCs

0
local intel

MITRE techniques

ATT&CK

Tracked

Yes
Ransomware.live

🔥 Leak-Site Victims (4)

VictimCountryPublishedDomain
ticketclub-it 2021-12-30T10:10:48.121036+00:00
bankjatim-co-id 2021-12-30T10:10:48.095882+00:00
salesplaypos-com 2021-12-30T10:10:48.071436+00:00
unexca-edu-ve 2021-12-30T10:10:48.039776+00:00

Source: Ransomware.live leak-site monitoring (cached, offline-safe).

📁 Case Management

+ New case from this

🏹 Add to case

Attach blacktor (Actor / APT) and pull all linked entities:

🧭 Intelligence disciplines

CYBINT →OSINT →HUMINT →GEOINT →
Live group profile & victims via Ransomware.live; ATT&CK technique hints are a static reference for well-known groups. All network calls cached & offline-safe.
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php