NEW: Group Profiler — instant APT intel lookup. Try it →

BlackTech

G0098 China MITRE ATT&CK →

Also known as: Palmerworm

Overview

BlackTech is a suspected Chinese cyber espionage group that has primarily targeted organizations in East Asia--particularly Taiwan, Japan, and Hong Kong--and the US since at least 2013. BlackTech has used a combination of custom malware, dual-use tools, and living off the land tactics to compromise media, construction, engineering, electronics, and financial company networks.

Naming & attribution

BlackTech is tracked under 2 names across the industry. It uses 14 documented ATT&CK techniques — more than 40% of the 174 groups tracked here. Activity attributed since at least 2013.

Who calls this group what — MITRE lists each alias with the report that used it, but not which vendor coined it.
NameFirst reported by
PalmerwormThreat Intelligence

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • Elderwood China — 5 shared techniques (28% overlap)
  • Ferocious Kitten Iran — 4 shared techniques (25% overlap)
  • Mofang China — 4 shared techniques (25% overlap)
  • Transparent Tribe Pakistan — 5 shared techniques (22% overlap)
  • WIRTE — 7 shared techniques (21% overlap)
  • EXOTIC LILY — 5 shared techniques (21% overlap)

Capabilities

  • Exploitation of public-facing / client applications — ATT&CK T1190, T1203
  • Custom malware/implant development — ATT&CK: 5 attributed custom malware families

TTPs — 14 techniques across 6 tactics

Resource Development

Stealth

Discovery

Lateral Movement

  • T1021.004 SSH

Tools & malware (6)

PLEAD · Kivars · PsExec · TSCookie · Flagpro · Waterbear

Reporting (3)