BlackOasis

MITRE ATT&CK: G0063 View on attack.mitre.org

Aliases: BlackOasis

Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 11:56:57

Targeted industries: government-and-public-sector media-and-entertainment education-and-nonprofits

Targeted regions: country_code:ae country_code:sa country_code:jo country_code:eg

Context

BlackOasis is a Middle Eastern threat group that is believed to be a customer of Gamma Group. The group has shown interest in prominent figures in the United Nations, as well as opposition bloggers, activists, regional news correspondents, and think tanks. A group known by Microsoft as NEODYMIUM is reportedly associated closely with BlackOasis operations, but evidence that the group names are aliases has not been identified.

Detection coverage

  • 87 Sigma rules

Malware & tools used

  • Obfuscated Files or Information (attack-pattern)

Reports & references

  • Kaspersky — 82732 (report)
  • Mandiant — Zero Day Used To Distribute Finspy (report)
  • MITRE ATT&CK — G0063 (report)
  • Kaspersky — 79332 (report)
  • cyberscoop.com — Middle Eastern Hacking Group Using Finfisher Malware Conduct International Espionage (report)

External references