Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory

BlackVortex1

Also known asblackvortex1

BlackVortex1 is a cybercriminal persona linked in the provided reporting to the emerging ransomware-as-a-service operation ShadowByt3$ / ShadowByt3s. The handle was observed across multiple cybercrime-related forums, including DarkForums, BreachForums-style profiles, and Cracked.sh, with account creation concentrated between late 2025 and early 2026. Reporting states that a DarkForums thread explicitly connected BlackVortex1 to ShadowByt3$, and that the repeated use of the handle across platforms appeared intended to build cross-platform visibility. The accounts were described as having low reputation and limited engagement. BlackVortex1 was tied to advertising ShadowByt3$'s RaaS offering on Cracked.sh. The advertised model offered a 70/30 revenue split in favor of affiliates, allowed participants with existing corporate access to join without an upfront fee, and allowed others to join by paying USD 250 in cryptocurrency. The offering also stated that affiliates could rely on the operator for parts of the negotiation process. In the broader ShadowByt3$ ecosystem described in the content, associated infrastructure included onion leak sites, mirrored onion domains, Telegram channels, ProtonMail, TOX, and cryptocurrency payment options in Bitcoin, Ethereum, and Monero. Telegram was reportedly used to announce leaks, share partial datasets, direct users to downloads, issue extortion messaging, and recruit collaborators with corporate access. The content also states that a threat actor using the moniker BlackVortex1 posted on a dark web forum claiming to have exfiltrated Starbucks intellectual property, in an incident attributed by the reporting to ShadowByt3s. In that case, the actor claimed theft of approximately 10GB of proprietary source code and operational firmware allegedly obtained from a misconfigured Amazon S3 bucket named "sbux-assets," and an extortion deadline was issued threatening public release if payment was not made. Based on the provided content, BlackVortex1 should be understood as a forum persona associated with promotion and recruitment activity for ShadowByt3$ / ShadowByt3s rather than a separately established intrusion set. No nation-state attribution is stated in the content.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

12 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

9 of 15 tactics15 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
1 technique
T1598
Phishing for Information
TA0042
Resource Development
2 techniques
T1583
Acquire Infrastructure
T1588
Obtain Capabilities
T1588.004
Digital Certificates
TA0001
Initial Access
1 technique
T1133×2
External Remote Services
TA0003
Persistence
1 technique
T1133×2
External Remote Services
TA0006
Credential Access
1 technique
T1552
Unsecured Credentials
T1552.001
Credentials In Files
TA0009
Collection
2 techniques
T1213
Data from Information Repositories
T1530×2
Data from Cloud Storage
TA0011
Command and Control
1 technique
T1071
Application Layer Protocol
TA0010
Exfiltration
2 techniques
T1537
Transfer Data to Cloud Account
T1567×3
Exfiltration Over Web Service
TA0040
Impact
2 techniques
T1486×2
Data Encrypted for Impact
T1657
Financial Theft
IOCS

Observables

8 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping12

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables8

Domains, IPs, and hashes tied to this actor, refreshed continuously.