About this actor
[BlackOasis](https://attack.mitre.org/groups/G0063) is a Middle Eastern threat group that is believed to be a customer of Gamma Group. The group has shown interest in prominent figures in the United Nations, as well as opposition bloggers, activists, regional news correspondents, and think tanks. (Citation: Securelist BlackOasis Oct 2017) (Citation: Securelist APT Trends Q2 2017) A group known by Microsoft as [NEODYMIUM](https://attack.mitre.org/groups/G0055) is reportedly associated closely with [BlackOasis](https://attack.mitre.org/groups/G0063) operations, but evidence that the group names are aliases has not been identified. (Citation: CyberScoop BlackOasis Oct 2017)
Source: MITRE ATT&CK
Names & naming systems
Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.
MITRE ATT&CKG-number catalogue id
Unclassifiedno scheme matched
How we know this
- Data origin
- MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
- Techniques
- MITRE ATT&CK STIX mappings — 1 ATT&CK technique on file.
- Named victims
- None on file.
Thin data: Only 1 ATT&CK technique mapped — a thin behavioural profile; absence is not evidence of a narrow toolkit.
See how actor data is built for the full pipeline.
Activity timeline
No activity events recorded.
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
| No attributed CVEs. | |||||
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
AC-3 | 1 / 1 | 100% |
CM-2 | 1 / 1 | 100% |
CM-6 | 1 / 1 | 100% |
CM-7 | 1 / 1 | 100% |
SI-2 | 1 / 1 | 100% |
SI-3 | 1 / 1 | 100% |
SI-4 | 1 / 1 | 100% |
SI-7 | 1 / 1 | 100% |
Co-occurring actors
None.
Similar actors
Similar TTPs
- Moafee 0.50
- Putter Panda 0.14
- Group5 0.14
- Mofang 0.11
- Gallmaker 0.09