Grupo hacktivista

BLACKNET-00 Ransomware

BlackNet is profiled here primarily as BLACKNET-00, a ransomware and crimeware framework promoted in the Infrastructure Destruction Squad ecosystem. Public reporting describes it as an accessible commercial framework advertised with encryption, data theft, evasion, persistence, remote control and Telegram-based control features.

Public reporting and vendor analysis emphasize that many BLACKNET-00 capabilities remain operator-claimed and require independent technical validation. The intelligence significance is not that the advertised features are novel, but that the actor attempts to package them into a low-cost, beginner-friendly framework with source-code sale claims and GUI-oriented access.

The actor environment blends hacktivist branding and profit-seeking crimeware distribution. KELA reporting states that Infrastructure Destruction Squad announced BLACKNET-00 in February 2026 as economically focused, while later forum activity explicitly connected Infrastructure Destruction Squad to the BLACKNET-00 ransomware organization.

INFERENCE (confidence: medium-high): BLACKNET-00 represents an enablement risk: it may lower the technical barrier for unsophisticated actors to attempt ransomware, data theft, remote control and extortion workflows even if individual features are not all technically mature.

Creado por iQBlack CTI Team
Colaboradores 1
Última actualización 2026-08-19

ATT&CK

MITRE ATT&CK

T1005Data from Local System
T1056.001Keylogging
T1102Web Service
T1113Screen Capture
T1123Audio Capture
T1125Video Capture
T1486Data Encrypted for Impact
T1552.004Private Keys
T1555.003Credentials from Web Browsers
T1562.001Disable or Modify Tools
T1587.001Malware

Research

OSINT seleccionado