NEW: Group Profiler — instant APT intel lookup. Try it →

← threatfilter.dev / all groups / BlackTech

BlackTech

G0098 China MITRE ATT&CK →

Also known as: Palmerworm

Overview

BlackTech is a suspected Chinese cyber espionage group that has primarily targeted organizations in East Asia--particularly Taiwan, Japan, and Hong Kong--and the US since at least 2013. BlackTech has used a combination of custom malware, dual-use tools, and living off the land tactics to compromise media, construction, engineering, electronics, and financial company networks.

Capabilities

  • Exploitation of public-facing / client applications — ATT&CK T1190, T1203
  • Custom malware/implant development — ATT&CK: 5 attributed custom malware families

TTPs — 14 techniques across 6 tactics

Resource Development

Stealth

Discovery

Lateral Movement

  • T1021.004 SSH

Tools & malware (6)

PLEAD · Kivars · PsExec · TSCookie · Flagpro · Waterbear

Reporting (3)