BTC $62360.1590
ETH $3157.9177
BNB $584.1815
SOL $134.7380
stETH $3155.2763
XRP $0.5057
DOGE $0.1406
TON $5.2504
ADA $0.4530
AVAX $33.2149
wstETH $3679.9658
TRX $0.1188
WETH $3154.2740
WBTC $62306.4033
DOT $6.5042
BCH $452.5282
LINK $13.9112
MATIC $0.6983
UNI $7.5794
LTC $83.4930
ICP $13.1908
DAI $0.9998
FDUSD $1.0004
CAKE $2.6700
NEAR $6.8065
RNDR $7.6920
IMX $2.0044
ETC $27.0784
HBAR $0.1033
STX $2.3670
MNT $1.0276
FIL $5.9051
OKB $51.1969
PEPE $0.0000
VET $0.0382
WIF $2.7301
TAO $399.6160
ATOM $7.9717
KAS $0.1111
MKR $2788.9916
GRT $0.2483
USDE $0.9993
FET $2.1180
AR $35.4053
XMR $125.2637
INJ $25.1448
XLM $0.1101
BTC $62360.1590
ETH $3157.9177
BNB $584.1815
SOL $134.7380
stETH $3155.2763
XRP $0.5057
DOGE $0.1406
TON $5.2504
ADA $0.4530
AVAX $33.2149
wstETH $3679.9658
TRX $0.1188
WETH $3154.2740
WBTC $62306.4033
DOT $6.5042
BCH $452.5282
LINK $13.9112
MATIC $0.6983
UNI $7.5794
LTC $83.4930
ICP $13.1908
DAI $0.9998
FDUSD $1.0004
CAKE $2.6700
NEAR $6.8065
RNDR $7.6920
IMX $2.0044
ETC $27.0784
HBAR $0.1033
STX $2.3670
MNT $1.0276
FIL $5.9051
OKB $51.1969
PEPE $0.0000
VET $0.0382
WIF $2.7301
TAO $399.6160
ATOM $7.9717
KAS $0.1111
MKR $2788.9916
GRT $0.2483
USDE $0.9993
FET $2.1180
AR $35.4053
XMR $125.2637
INJ $25.1448
XLM $0.1101
  • Catalog
  • Blog
  • Tor Relay
  • Jabber
  • One-Time notes
  • Temp Email
  • What is TOR?
  • We are in tor
  • The political motives of the new group make Israeli companies nervous


    Cybersecurity firm Cyble has uncovered a new politically motivated group, BlackMagic, which is allegedly linked to Iran and is targeting companies in Israel.

    According to Cyble analysts, the ransomware group uses a double ransomware method - first extracting the victim's files and then encrypting them. BlackMagic has more than 10 victim companies on its account, all of them from Israel but of Iranian origin.

    It is noteworthy that the ransom note does not contain information about the ransom itself. Instead, hackers indicate their social networks used to disclose the victim's data. This means that the ransomware group is interested in selling the stolen data and not in getting a ransom from their victims.

    BlackMagic claims to have stolen 50GB of data from transport companies in Israel, as well as the sensitive data of more than 65% of the country's citizens. According to the researchers, the hackers are selling stolen data on several cybercrime forums. The attackers also deface the victim’s website.

    “Destroying logistics companies and preventing packages from being sent,” BlackMagic said in a darknet statement.

    Also in the process of encrypting data, attackers place a ransom note in all folders of the target system, and then add the ".BlackMagic" extension to the files.

    After that, the hackers create a BAT file on the C drive, which removes all traces after the data is encrypted. The BAT file also replaces the desktop background of the compromised device with an image that is likely the BlackMagic logo. The picture contains the logos of previous victims of the group.

    Based on the activities of BlackMagic, experts suspect that the hackers are politically motivated, but it is unclear how they will develop in the future.

    Author DeepWeb
    Palo Alto Networks: Vice Society is one of the most influential ransomware groups of 2022
    Apple has developed a new data encryption system for iCloud

    Comments 0

    Add comment