Introduction
BlackTech is a suspected Chinese cyber espionage group that has primarily targeted organizations in East Asia–particularly Taiwan, Japan, and Hong Kong–and the US since at least 2013. BlackTech has used a combination of custom malware, dual-use tools, and living off the land tactics to compromise media, construction, engineering, electronics, and financial company networks. TrendMicro BlackTech June 2017 Symantec Palmerworm Sep 2020 Reuters Taiwan BlackTech August 2020
Activities and Tactics
Country of Origin: 🇨🇳 China
Notable Campaigns
- PLEAD
- Shrouded Crossbow
- Waterbear
Tactics, Techniques, and Procedures (TTPs)
- T1566.002 Spearphishing Link
- T1204.001 Malicious Link
- T1588.003 Code Signing Certificates
- T1046 Network Service Discovery
- T1588.002 Tool
- T1190 Exploit Public-Facing Application
- T1021.004 SSH
- T1106 Native API
- T1203 Exploitation for Client Execution
- T1566.001 Spearphishing Attachment
- T1036.002 Right-to-Left Override
- T1574.001 DLL
- T1204.002 Malicious File
- T1588.004 Digital Certificates
ATT&CK technique IDs (denormalized)
- T1021.004
- T1036.002
- T1046
- T1106
- T1190
- T1203
- T1204.001
- T1204.002
- T1566.001
- T1566.002
- T1574.001
- T1588.002
- T1588.003
- T1588.004
Notable Indicators of Compromise (IOCs)
No curated IOCs are currently published for this actor. This section will be updated when stable, attributable indicators are available.
Malware and Tools
- BlackEnergy
- Backdoor.Oldrea
- CloudDuke
- Rover
- BLACKCOFFEE
- Blackshades
- BlackNix
- CyberGate
- Cyber Eye RAT
- HTTP WEB BACKDOOR
- BendyBear:
MITRE ATT&CK Software
- PLEAD (S0435) — malware
- Kivars (S0437) — malware
- PsExec (S0029) — tool
- TSCookie (S0436) — malware
- Flagpro (S0696) — malware
- Waterbear (S0579) — malware
Attribution and Evidence
Country of Origin: China Additional attribution information pending cataloguing.
References
[1] mitre-attack [3] TrendMicro BlackTech June 2017 Bermejo, L., et al. (2017, June 22). Following the Trail of BlackTech’s Cyber Espionage Campaigns. Retrieved May 5, 2020. [4] IronNet BlackTech Oct 2021 Demboski, M., et al. (2021, October 26). China cyber attacks: the current threat landscape. Retrieved March 25, 2022. [5] Reuters Taiwan BlackTech August 2020 Lee, Y. (2020, August 19). Taiwan says China behind cyberattacks on government agencies, emails. Retrieved April 6, 2022. [6] Symantec Palmerworm Sep 2020 Threat Intelligence. (2020, September 29). Palmerworm: Espionage Gang Targets the Media, Finance, and Other Sectors. Retrieved March 25, 2022.