You are exploring the Free preview. To unlock full read-only access to all public profiles and in-app notifications, create a free research account. For analyst / premium plans capabilities (editing, advanced tabs, exports), please contact us

Threat Actor Characterization

You’re viewing the read-only version. Sign in for analyst tools (editors, promote draft, file/relations management, etc.)
Surabaya Black Hat

Surabaya Black Hat

ID: 93c9314525c96b0828f594faeab0139886064
Hacktivist Group Collective Defacement Crew Hacktivism
Threat types: Intrusion, Ransomware, Blackmail, Cybercrime
Indonesia IDN
Updated: 2026-02-23
Created: 2025-10-17
Progress: 76% Completeness: 79% Freshness: 70%
Operation zone: Indonesia
Aliases Limited alias preview
SBH Surabaya BlackHat Su**************
Showing 2 of 3 aliases in free preview.
Actor Network Graph
Open Network Graph
Read-only preview for anonymous visitors. Sign in with a free Research account for full workspace.
MITRE ATT&CK®

Surabaya Black Hat (SBH) — Indonesian cybercriminal collective founded in 2011 and exposed in March 2018 for hundreds to thousands of website compromises across 40+ countries. Police and press cite SQL injection, a 707-member Telegram group for data sharing (later disbanded), and profit-motivated extortion. SBH also publishes its own webshell (SBH Shell v2.5) on GitHub.


Technique Technique name Tactics Evidence
T1190 Exploit Public-Facing Application TA0001
  • 2018-03-13 — Detik: Three SBH students breached systems in ~5 minutes using SQL injection. · ref
  • 2018-03-14 — Jakarta Post: Police report SBH hacked companies’ systems across many countries. · ref
T1505.003 Web Shell TA0003
  • 2017-11-27 — GitHub: SBH Shell v2.5 repository lists features (mass deface, cPanel functions, fake error screen, password). · ref
T1491.002 External Defacement TA0040
  • 2013-01-16 — Detik: FarhatAbbasCenter.com defaced; deface page shows SurabayaBlackHat.org reference and a contact email. · ref
  • 2013-01-16 — LinuxSec blog recounts Farhat Abbas defacement and community growth. · ref
T1657 Financial Theft TA0040
  • 2018-03-14 — Police statements via Tirto: SBH sought payment via PayPal/Bitcoin after hacks. · ref
T1585 Establish Accounts TA0042
  • 2018-03-15 — CNN Indonesia: ~707 members in SBH Telegram group used for data sharing; group disbanded post-arrests. · ref
Strategic Intelligence
Limited preview
Last updated: 2025-10-19T00:31:38+00:00
Surabaya Black Hat (SBH) — Indonesian Cybercriminal Collective

CLASSIFICATION: Unclassified / Open Source


Executive Summary

Surabaya Black Hat (SBH) is an Indonesian underground collective active since September 20, 2011, straddling the country’s defacement scene and profit-motivated intrusions. Media and police reporting in March 2018—triggered by an FBI referral—document hundreds to thousands of website compromises across 40+ countries, SQL injection as a common vector, and extortion for payment via PayPal/Bitcoin. Group infrastructure included a web forum and a sizable Telegram community (approx. 707 members) used for data sharing, which disbanded after arrests. SBH also maintains a public GitHub organization hosting the SBH Shell v2.5 (webshell/defacement toolkit). Overall assessment: criminal crew with organized tooling and social reach; technical depth moderate, impact amplified by scale and publicity. Confidence: high based on mainstream Indonesian press, GitHub artifacts, and law-enforcement statements.

  • Origin & brand: Underground community founded 2011-09-20 with forum + Facebook group; publicity spikes correlated with high-profile defacements (e.g., Farhat Abbas).
  • Goalset: Mixed—status in local scene, some hacktivist-style defacements for clout, but primary monetization via hacking-for-profit and blackmail/ransom. tirto.id
  • Comms: Forum, Facebook, and later Telegram (707 members, shut down after arrests). CNN Indonesia
  • Recruitment & reach: Rapid community growth after media-covered defacements; forum/FB seen as on-ramps for novices, with seniors coaching. LinuxSec Exploit
  • Narrative leverage: Indonesian press coverage and social chatter magnified SBH’s notoriety. The Jakarta Post
  • Operational discipline: Public GitHub presence for tooling suggests semi-organized development and shared tradecraft. GitHub
Full strategic intelligence is available in Analyst and Premium plans.
Executive Analyst Brief for CISO
Empty Limited preview
No content yet.
Tip: Hover the section title to learn what’s included in Analyst / Premium plans.
Executive brief now
Saved successfully.
Hunting Playbook
Empty Limited preview
No content yet.
Tip: Hover the section title to learn what’s included in Analyst / Premium plans.
Hunting Playbook now
Saved successfully.
IOC Appendix
Empty Limited preview
No content yet.
IOC Appendix now
Saved successfully.
OSINT Library
Empty Limited preview
No content yet.
OSINT Library now
Saved successfully.
Social Medial & Communication
SOCMINT integrated: 0/16

Address Verification SOCMINT
x.com/sby********* Restricted Not integrated
Address Verification SOCMINT
www.facebook.com/sur************* Restricted Not integrated
www.facebook.com/gro******************* Restricted Not integrated
Address Verification SOCMINT
t.me/sur************* Restricted Not integrated
Address Verification SOCMINT
instagram.com/sur************* Restricted Not integrated
www************************************ Restricted Not integrated
Address Verification SOCMINT
ro**@surabayablackhat.org Restricted Not integrated
su***********@gmail.com Restricted Not integrated
Address Verification SOCMINT
surabayablackhatofficial.eu5.org Restricted Not integrated
surabayablackhat.6te.net Restricted Not integrated
surabayablackhat.org Restricted Not integrated
donate.surabayablackhat.org Restricted Not integrated
forum.surabayablackhat.org Restricted Not integrated
blog.surabayablackhat.org/sbh****** Restricted Not integrated
laravel.io/ind**************************** Restricted Not integrated
Address Verification SOCMINT
github.com/Sur************* Restricted Not integrated
Notes: preview mode hides sensitive social/contact details.
Reference Images/Associated Evidence Limited

Showing 1–7 of 7 images
SurabayaBlackhat Shell 2.5 (screenshot) Free Preview
SurabayaBlackhat Shell 2.5 (screenshot)
Hacked website evidence Free Preview
Hacked website evidence
Members of SBH face a press conference at the Jakarta Police headquarters in South Jakarta on March 13, 2018 Free Preview
Members of SBH face a press conference at the Jakarta Police headquarters in South Jakarta on March 13, 2018
Logo variant used in t-shirt Free Preview
Logo variant used in t-shirt
Banner used in social media account Free Preview
Banner used in social media account
Logo variant Free Preview
Logo variant
Logo variant Free Preview
Logo variant
Showing 4 of 7 images in preview mode. Additional evidence is restricted for Analyst and Premium plans.