Uptime Hamster: 11d 15h 10mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza Blackatom

Blackatom

0 incidentes 0 paises 0 sectores apt PS Ultimo: -
Ver en IntelTracker → APTTrail →
Blackatom is a cyber espionage group, also identified by Google's Threat Analysis Group (TAG), and is assessed with high confidence to be a Palestine-based entity likely linked to Hamas. The group's primary motivation is to collect sensitive information and documents from high-value targets to gather intelligence, supporting military or Palestinian state objectives. What specifically sets Blackatom apart is its use of intricate and elaborate social engineering lures, specifically crafted for niche high-value targets, often involving highly focused phishing campaigns that target a very limited number of entities in each operation. Researchers have tracked the group, also known by the aliases Molerats and Proofpoint's TA402 designation, for over a decade. Historically, this group has also been referred to as Gaza Cybergang, Frankenstein, and WIRTE. It is important to note that Blackatom is distinct from APT28 and Fancy Bear, which are unrelated threat actors.
Tecnicas MITRE
T1566.001, T1078, T1071.001
Tipo
apt
Pais origen
PS
Motivacion
-
Impacto
25
Actualizado
Sat, 17 Fe

Paises objetivo (SOCRadar)

Hong KongIsraelJapanPalestine, State ofTaiwan, Province of ChinaUnited States

Sectores objetivo (SOCRadar)

Energy & Utilities Transportation&WarehousingInformation ServicesPublic AdministrationJustice & Safety ActivitiesSpace & DefenseNational Security&International AffairsSoftware PublishersComputer Design & ServicesAircraft Manufacturing