Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Blackwood

Description

Blackwood is a China-aligned APT group that has been active since at least 2018. They primarily engage in cyberespionage operations targeting individuals and companies in China, Japan, and the United Kingdom. Blackwood utilizes sophisticated techniques such as adversary-in-the-middle attacks to deliver their custom implant, NSPX30, through updates of legitimate software. They also have the capability to hide the location of their command and control servers by intercepting traffic generated by the implant.

AI Analysis

· 1 week ago

Executive Summary

Blackwood is a China-aligned advanced persistent threat (APT) group active since 2018, specializing in cyberespionage against targets in China, Japan, and the UK. They use sophisticated adversary-in-the-middle attacks to deliver custom implants like NSPX30 through compromised software updates, while employing traffic interception to obscure command-and-control infrastructure locations.

Goals & Targeting

Blackwood's strategic objectives align with China's broader cyberespionage interests, focusing on intellectual property theft, state secrets acquisition, and disruption of adversarial nations' technological and defense sectors. Their targeting of China, Japan, and the UK reflects a focus on regions with advanced research capabilities and strategic geopolitical significance. Typical victims include technology firms, academic institutions, and government agencies involved in cybersecurity, telecommunications, and defense-related research.

Enhanced Description

Blackwood operates as a state-sponsored APT group with a focus on cyberespionage, targeting government entities, technology firms, and research institutions within China, Japan, and the United Kingdom. Their operations leverage sophisticated techniques, including adversary-in-the-middle (MITM) attacks to inject malicious payloads into legitimate software update channels, enabling stealthy deployment of their custom implants. A key component of their operations is the NSPX30 implant, which establishes covert communication channels while avoiding detection through obfuscation of command-and-control (C2) infrastructure locations. By intercepting traffic generated by the implant, Blackwood can dynamically route C2 communications through compromised networks, making attribution and tracking significantly more challenging. These capabilities suggest a high level of technical sophistication and long-term persistence in targeted environments.

Key Capabilities

  • Adversary-in-the-middle (MITM) attacks for payload delivery
  • Custom implant deployment (NSPX30)
  • C2 infrastructure obfuscation via traffic interception
  • Exploitation of software update mechanisms for persistent access

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Command and Control
Defense Evasion

ATT&CK Techniques

T1219.001 - Adversary-in-the-Middle
T1055 - Payload Delivery via Custom Implants
T1566.001 - Phishing
T1570.001 - C2 Obfuscation
T1110.002 - Software Update Compromise

Software / Tooling

NSPX30 Implant
Legitimate Software Update Exploitation Frameworks

Campaigns & Victims

Blackwood's campaigns, active since at least 2018, demonstrate a focus on long-term reconnaissance and data exfiltration. Their operational tempo includes periodic updates to TTPs, with a preference for leveraging trusted software channels to avoid detection. Notable operations involve compromising enterprise software update servers to distribute NSPX30, followed by sustained access to extract sensitive information from victim networks.

IOC Patterns

  • Software update package tampering with embedded NSPX30 payloads
  • C2 traffic routed through intercepted implant-generated DNS queries
  • Anomalous network traffic patterns from compromised endpoints during off-hours

Recommended Actions

  • Implement strict software update verification processes using cryptographic signatures
  • Monitor DNS query patterns for irregularities in endpoint communication
  • Deploy network traffic analysis tools to detect C2 obfuscation techniques
  • Conduct regular red team exercises to identify MITM attack vulnerabilities
  • Segment sensitive networks to limit lateral movement post-compromise

Suggested Tags

APT
cyberespionage
China-aligned
software supply chain attack
implant-based persistence

Confidence Assessment

The threat profile is based on confirmed cyberespionage activities and technical indicators associated with Blackwood's operations. Confidence is high for China alignment and core TTPs, but gaps exist in understanding full campaign scope, secondary toolkits, and potential links to other China-aligned APT groups. Limited public reporting restricts confirmation of specific motivations and full victim lists.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
Backdoor / C2
cyberespionage
China-aligned
software supply chain attack
implant-based persistence

Details

Type
Unknown
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.