THREAT_ACTOR · G0063
BlackOasis
Also known as: BlackOasis
Profile
BlackOasis is a Middle Eastern threat group that is believed to be a customer of Gamma Group. The group has shown interest in prominent figures in the United Nations, as well as opposition bloggers, activists, regional news correspondents, and think tanks. A group known by Microsoft as NEODYMIUM is reportedly associated closely with BlackOasis operations, but evidence that the group names are aliases has not been identified.
MITRE ATT&CK ↗Techniques
1 ATT&CK techniques attributed to this actor.
Related corpus activity
8,891 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to BlackOasis.
| Indicator | Type | Family | Sev | Src |
|---|---|---|---|---|
| cve-2017-18377 | cve | — | 85 | 1 |
| cve-2023-52271 | cve | ransomware | 85 | 3 |
| cve-2026-3102 | cve | — | 85 | 3 |
| cve-2025-34117 | cve | — | 85 | 1 |
| cve-2026-0740 | cve | — | 85 | 1 |
| cve-2025-61155 | cve | ransomware | 85 | 3 |
| cve-2025-68670 | cve | — | 85 | 2 |
| cve-2014-2321 | cve | — | 85 | 1 |
| cve-2020-17456 | cve | — | 85 | 1 |
| cve-2025-2492 | cve | — | 85 | 2 |
| cve-2013-7471 | cve | — | 85 | 1 |
| cve-2026-1969 | cve | — | 85 | 1 |
| cve-2025-34085 | cve | — | 85 | 1 |
| cve-2025-7852 | cve | — | 85 | 1 |
| cve-2013-3307 | cve | — | 85 | 2 |
| cve-2025-11837 | cve | — | 85 | 2 |
| cve-2024-1781 | cve | — | 85 | 1 |
| cve-2018-8007 | cve | — | 85 | 1 |
| cve-2023-44976 | cve | ransomware | 85 | 2 |
| cve-2021-4045 | cve | — | 85 | 1 |
| cve-2020-22653 | cve | — | 85 | 2 |
| cve-2020-22658 | cve | — | 85 | 2 |
| cve-2022-47945 | cve | — | 85 | 1 |
| cve-2016-5681 | cve | — | 85 | 2 |
| cve-2021-25646 | cve | — | 85 | 1 |
| cve-2021-29441 | cve | — | 85 | 1 |
| cve-2026-3844 | cve | — | 85 | 1 |
| cve-2025-12057 | cve | — | 85 | 1 |
| cve-2025-7443 | cve | — | 85 | 1 |
| cve-2025-1055 | cve | ransomware | 85 | 3 |
Showing the top 30 by severity of 8,891.