Menu
Browse

Cyber Threat Actor: Black Spark

Updated 2026-08-21 17:16
Actor Type Location Known Incidents
 Icon
Activist
Russia
1 incident
Characteristics
Threat actor characteristics available to members
Profile

Black Spark is an alias used by a threat actor that presents itself as an underground movement based in Russia. The group has publicly identified as pro‑Ukraine and has disseminated a manifesto on Telegram advocating armed resistance against the Russian state. No further details about its organizational structure, size, or leadership are available in the open source material. The actor’s self‑description emphasizes ideological motivation rather than financial gain, and it has not been linked to any state sponsor or criminal consortium in publicly attributed reporting.

In the only publicly reported operation attributed to Black Spark, the group claimed responsibility for a compromise of Microolap, a Russian network monitoring firm. According to the actor’s own statements, they maintained presence within Microolap’s environment for over a month, gaining access to the EtherSensor monitoring platform and extracting data from several of the firm’s customers, including Russian Railways, Goznak, VTB Bank and its leasing arm, and NEK.TECH. Microolap’s investigation indicated that the intrusion was limited to rarely used development systems hosted by a third party, an outdated website version, and an old Bitrix24 CRM, all of which were isolated from critical infrastructure. The actor’s tactics therefore appear to involve exploiting legacy or poorly maintained external assets to establish an initial foothold before moving laterally to internal monitoring tools. No specific malware families or custom tooling were disclosed in the available reports. The incident is cited as a representative example of Black Spark’s activity, illustrating its focus on targeting Russian entities that provide network visibility and its claim of obtaining customer‑level data for propaganda or disruptive purposes.

Incidents
Attributed incidents available to members
1 incident
Sources
Sources available to members
0 sources