Threat Actor Characterization
Surabaya Black Hat
ID: 93c9314525c96b0828f594faeab0139886064| SBH | Surabaya BlackHat | Su************** | — |
Actor Network Graph
Open Network GraphMITRE ATT&CK®
Surabaya Black Hat (SBH) — Indonesian cybercriminal collective founded in 2011 and exposed in March 2018 for hundreds to thousands of website compromises across 40+ countries. Police and press cite SQL injection, a 707-member Telegram group for data sharing (later disbanded), and profit-motivated extortion. SBH also publishes its own webshell (SBH Shell v2.5) on GitHub.
| Technique | Technique name | Tactics | Evidence |
|---|---|---|---|
| T1190 | Exploit Public-Facing Application | TA0001 | |
| T1505.003 | Web Shell | TA0003 |
|
| T1491.002 | External Defacement | TA0040 | |
| T1657 | Financial Theft | TA0040 |
|
| T1585 | Establish Accounts | TA0042 |
|
CLASSIFICATION: Unclassified / Open Source
Executive Summary
Surabaya Black Hat (SBH) is an Indonesian underground collective active since September 20, 2011, straddling the country’s defacement scene and profit-motivated intrusions. Media and police reporting in March 2018—triggered by an FBI referral—document hundreds to thousands of website compromises across 40+ countries, SQL injection as a common vector, and extortion for payment via PayPal/Bitcoin. Group infrastructure included a web forum and a sizable Telegram community (approx. 707 members) used for data sharing, which disbanded after arrests. SBH also maintains a public GitHub organization hosting the SBH Shell v2.5 (webshell/defacement toolkit). Overall assessment: criminal crew with organized tooling and social reach; technical depth moderate, impact amplified by scale and publicity. Confidence: high based on mainstream Indonesian press, GitHub artifacts, and law-enforcement statements.
- Origin & brand: Underground community founded 2011-09-20 with forum + Facebook group; publicity spikes correlated with high-profile defacements (e.g., Farhat Abbas).
- Goalset: Mixed—status in local scene, some hacktivist-style defacements for clout, but primary monetization via hacking-for-profit and blackmail/ransom. tirto.id
- Comms: Forum, Facebook, and later Telegram (707 members, shut down after arrests). CNN Indonesia
- Recruitment & reach: Rapid community growth after media-covered defacements; forum/FB seen as on-ramps for novices, with seniors coaching. LinuxSec Exploit
- Narrative leverage: Indonesian press coverage and social chatter magnified SBH’s notoriety. The Jakarta Post
- Operational discipline: Public GitHub presence for tooling suggests semi-organized development and shared tradecraft. GitHub
Free Preview
Free Preview
Free Preview
Free Preview
Free Preview
Free Preview
Free Preview