BlackOasis
BlackOasis is a threat actor referenced in the provided content as using obfuscation and exploit-based intrusion tradecraft. The content states that BlackOasis used CVE-2017-0199 in the wild and was believed to be a customer of Gamma Group that utilized FinSpy. It also states that BlackOasis used first-stage shellcode containing a NOP sled with alternative instructions that was likely designed to bypass antivirus tools. Across the provided ATT&CK-annotated detection content, BlackOasis is associated with obfuscated files or information (T1027), including use of encoded PowerShell commands and Linux base64 decode activity passed to shell processes. The content places BlackOasis in Middle Eastern exploitation activity in 2017 alongside use of CVE-2017-0199. No additional aliases or sub-groups are provided beyond the name BlackOasis.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
1 malware family attributed to this actor across reporting.
Associated vulnerabilities
4 CVEs this actor has used in observed campaigns. 4 of them exploited in the wild.
We have previously reported on BlackOasis using other zero-days in the past; CVE-2016-4117 in May 2016, CVE-2016-0984 in June 2015, and CVE-2015-5119 in June 2015.
We have previously reported on BlackOasis using other zero-days in the past; CVE-2016-4117 in May 2016, CVE-2016-0984 in June 2015, and CVE-2015-5119 in June 2015.
We have previously reported on BlackOasis using other zero-days in the past; CVE-2016-4117 in May 2016, CVE-2016-0984 in June 2015, and CVE-2015-5119 in June 2015.
we did produce two reports revolving around the use of a zero-day exploit (CVE-2017-0199). The most notable involved an actor we refer to as BlackOasis and their usage of the exploit in-the-wild prior to its discovery.
Recent activity
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as an associated threat actor in the detection annotations for exploitation-related activity.
Listed as a threat actor associated with the Linux base64-to-shell execution detection analytic.
Listed as a threat actor associated with the Obfuscated Files or Information (T1027) defense evasion technique, specifically relevant to base64 decoding on Linux.
Referenced as a threat actor associated with use of obfuscated PowerShell encoded commands for defense evasion.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.