Blackwood is a China-aligned APT group that has been active since at least 2018. They primarily engage in cyberespionage operations targeting individuals and companies in China, Japan, and the United Kingdom. Blackwood utilizes sophisticated techniques such as adversary-in-the-middle attacks to deliver their custom implant, NSPX30, through updates of legitimate software. They also have the capability to hide the location of their command and control servers by intercepting traffic generated by the implant.
Executive Summary
Blackwood is a China-aligned advanced persistent threat (APT) group active since 2018, specializing in cyberespionage against targets in China, Japan, and the UK. They use sophisticated adversary-in-the-middle attacks to deliver custom implants like NSPX30 through compromised software updates, while employing traffic interception to obscure command-and-control infrastructure locations.
Goals & Targeting
Blackwood's strategic objectives align with China's broader cyberespionage interests, focusing on intellectual property theft, state secrets acquisition, and disruption of adversarial nations' technological and defense sectors. Their targeting of China, Japan, and the UK reflects a focus on regions with advanced research capabilities and strategic geopolitical significance. Typical victims include technology firms, academic institutions, and government agencies involved in cybersecurity, telecommunications, and defense-related research.
Enhanced Description
Blackwood operates as a state-sponsored APT group with a focus on cyberespionage, targeting government entities, technology firms, and research institutions within China, Japan, and the United Kingdom. Their operations leverage sophisticated techniques, including adversary-in-the-middle (MITM) attacks to inject malicious payloads into legitimate software update channels, enabling stealthy deployment of their custom implants. A key component of their operations is the NSPX30 implant, which establishes covert communication channels while avoiding detection through obfuscation of command-and-control (C2) infrastructure locations. By intercepting traffic generated by the implant, Blackwood can dynamically route C2 communications through compromised networks, making attribution and tracking significantly more challenging. These capabilities suggest a high level of technical sophistication and long-term persistence in targeted environments.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Blackwood's campaigns, active since at least 2018, demonstrate a focus on long-term reconnaissance and data exfiltration. Their operational tempo includes periodic updates to TTPs, with a preference for leveraging trusted software channels to avoid detection. Notable operations involve compromising enterprise software update servers to distribute NSPX30, followed by sustained access to extract sensitive information from victim networks.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The threat profile is based on confirmed cyberespionage activities and technical indicators associated with Blackwood's operations. Confidence is high for China alignment and core TTPs, but gaps exist in understanding full campaign scope, secondary toolkits, and potential links to other China-aligned APT groups. Limited public reporting restricts confirmation of specific motivations and full victim lists.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics