Pro-Ukraine hacker group Black Owl poses ‘major threat’ to Russia, Kaspersky says
一个鲜为人知的黑客组织BO Team(又称Black Owl)自2024年初活跃以来,对俄罗斯政府机构和关键行业发动了一系列破坏性网络攻击。该组织通过钓鱼邮件入侵系统后潜伏数周甚至数月再行动,并使用多种恶意工具如DarkGate后门和Babuk勒索软件进行破坏。其攻击目标主要集中在俄罗斯境内的国有企业及科技、电信和制造行业。与支持乌克兰的其他黑客组织不同,BO Team独立运作且策略独特,在俄罗斯网络威胁环境中显得尤为突出。 2025-6-2 15:46:24 Author: therecord.media(查看原文) 阅读量:38 收藏

A little-known hacking group has emerged as a major threat to Russian state institutions and critical industries, carrying out attacks aimed at causing maximum disruption and extracting financial gain, according to a new report.

BO Team, also known as Black Owl, has been active since early 2024 and appears to operate independently, with its own arsenal of tools and tactics, researchers at Russian cybersecurity firm Kaspersky said.

Among the group’s most disruptive operations was a cyberattack last month that reportedly wiped out about a third of Russia’s national electronic court filing system. Ukrainian military intelligence (HUR) previously said it cooperated with BO Team on several operations, including breaches of Russia’s federal digital signature authority and a scientific research center.

The group typically gains initial access to victims’ systems through phishing emails containing convincing malicious attachments. Once inside, BO Team may wait weeks or even months before taking action — an unusual delay for hacktivists, who typically aim to destroy or steal data quickly. The group’s evolving toolkit includes the backdoors DarkGate, BrockenDoor and Remcos.

After compromising a network, BO Team deletes backups and virtual infrastructure using tools like Microsoft’s SDelete, and in some cases deploys Babuk ransomware to encrypt data and demand payment, the researchers said. The hackers are known to disguise their malware as legitimate Windows software.

BO Team has exclusively targeted organizations in Russia, including state-run companies and entities in the technology, telecom and manufacturing sectors. The hackers often post about their attacks on Telegram — both to intimidate victims and draw media attention.

“BO Team is a serious threat to Russian organizations because of its unusual approach to cyberattacks,” Kaspersky said. Unlike other pro-Ukraine hacktivist groups, it shows little sign of coordination, collaboration, or tool-sharing with others — setting it apart in Russia’s current hacktivist landscape, researchers added.

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.


文章来源: https://therecord.media/pro-ukraine-hacker-group-black-owl-major-threat-russia
如有侵权请联系:admin#unsafe.sh