HOMETHREATSBlackJack
APT / THREAT GROUP

BlackJack

🇺🇦Ukraine-attributed
1
campaigns
1
aliases
Last seen:Mar 17, 2026

Intelligence Profile

Blackjack, a threat actor linked to Ukraine's security apparatus, has targeted critical Russian entities such as ISPs, utilities, and military infrastructure. They have claimed responsibility for launching cyberattacks resulting in substantial damage and data exfiltration. The group allegedly used the Fuxnet malware to target sensor gateways connected to internet-connected sensors, impacting infrastructure monitoring systems. Blackjack has also been involved in attacks against companies like Moscollector, causing disruptions and stealing sensitive data.

Threat Analysis

BlackJack is a known-sophistication threat actor attributed to Ukraine, engaged in cyber operations with a primary motivation of unknown activity patterns.

Known Campaigns

BlackJack — Active Operations March 2026

BlackJack is a unknown-motivation threat actor attributed to UA. Blackjack, a threat actor linked to Ukraine's security apparatus, has targeted critical Russian entities such as ISPs, utilities, and military infrastructure. They have claimed responsibility for launching cyberattacks resulting in substantial damage and data exfiltration. The gr...

ACTIVEMEDIUM2026

External References

Quick Facts

TypeAPT / Threat Group
Origin🇺🇦 Ukraine
Aliases1
SourceMalpedia

Also Known As

BlackJack

Research Links

Data sourced from Malpedia, Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Actor attribution is based on available intelligence and may be incomplete.