Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware Flagpro

Flagpro

TLP:CLEAR
Family

AI Analysis

· 19 hours ago

Executive Summary

Flagpro is a Windows downloader used by BlackTech to inject additional payloads into targeted defense and media organizations in Japan since 2020. It retrieves secondary malware from external C2 servers, potentially enabling espionage or sabotage once deeper stages are executed. Security teams should pre‑emptively block related URLs/IPs and monitor for abnormal download activity.

Enhanced Description

Flagpro is a Windows‑native first‑stage downloader that has been identified in the threat landscape as a component of BlackTech campaigns active since October 2020. The malware appears primarily against defense, media, and communications clients within Japan, serving to establish footholds before additional payloads are fetched from external command‑and‑control infrastructure. During execution Flagpro initiates network connections to download secondary malicious modules over HTTP/HTTPS. Preliminary analysis indicates it utilizes common obfuscation techniques to evade signature‑based detection, while attempting to blend with legitimate system processes. Once the additional components arrive, they may proceed with persistence mechanisms, credential harvesting or lateral movement. Because Flagpro functions only as a downloader, its direct impact on compromised hosts is limited until subsequent stages execute. Nonetheless, in the context of supply‑chain attacks and targeted espionage, the initial compromise can give adversaries access to sensitive technical data, intellectual property, or operational capabilities within critical defense-related infrastructures. The current intelligence suggests the malware has evolved modestly over time. However, without further disassembly or endpoint telemetry, details such as command‑and‑control structure, persistence techniques, and specific malicious modules remain unconfirmed.

Key Capabilities

  • Downloads secondary malicious modules via HTTP/HTTPS
  • Performs basic obfuscation to evade detection
  • Runs on Windows operating systems

ATT&CK Techniques

T1105
T1059

Recommended Actions

  • Block known Flagpro download URLs and IP addresses at the perimeter firewall or proxy Monitor outbound HTTP/HTTPS traffic for anomalous connections to external domains Deploy endpoint detection solutions that can flag suspicious process creation and downloader behavior Maintain up‑to‑date malware prevention tools and YARA rules for Flagpro signatures Educate users on avoiding phishing attachments that may contain the downloader

Suggested Tags

Flagpro
BlackTech
Downloader
Japan
DefenseSector
MediaCompanies

Confidence Assessment

The analysis is based on limited publicly available data, primarily a brief vendor report. Key technical details such as exact download mechanisms, encryption usage, persistence strategies, and post‑download payloads are not fully described, creating gaps in understanding the full threat vector. Further endpoint telemetry, code reverse engineering, and network capture data would improve confidence significantly.

Description

Flagpro is a Windows-based, first-stage downloader that has been used by BlackTech since at least October 2020. It has primarily been used against defense, media, and communications companies in Japan.(Citation: NTT Security Flagpro new December 2021)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.