BlackOasis
MITRE ATT&CK: G0063 View on attack.mitre.org
Aliases: BlackOasis
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 11:56:57
Targeted industries: government-and-public-sector media-and-entertainment education-and-nonprofits
Targeted regions: country_code:ae country_code:sa country_code:jo country_code:eg
Context
BlackOasis is a Middle Eastern threat group that is believed to be a customer of Gamma Group. The group has shown interest in prominent figures in the United Nations, as well as opposition bloggers, activists, regional news correspondents, and think tanks. A group known by Microsoft as NEODYMIUM is reportedly associated closely with BlackOasis operations, but evidence that the group names are aliases has not been identified.
Detection coverage
- 87 Sigma rules
Malware & tools used
- Obfuscated Files or Information (attack-pattern)
Reports & references
- Kaspersky — 82732 (report)
- Mandiant — Zero Day Used To Distribute Finspy (report)
- MITRE ATT&CK — G0063 (report)
- Kaspersky — 79332 (report)
- cyberscoop.com — Middle Eastern Hacking Group Using Finfisher Malware Conduct International Espionage (report)