Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors BlackTech

Also known as: Palmerworm, CIRCUIT PANDA, Temp.Overboard, HUAPI, G0098, T-APT-03, Manga Taurus, Red Djinn, Earth Hundun, Canary Typhoon, Mobwork, CAVERN CASTLE

Description

BlackTech is a suspected Chinese cyber espionage group that has primarily targeted organizations in East Asia--particularly Taiwan, Japan, and Hong Kong--and the US since at least 2013. BlackTech has used a combination of custom malware, dual-use tools, and living off the land tactics to compromise media, construction, engineering, electronics, and financial company networks.(Citation: TrendMicro BlackTech June 2017)(Citation: Symantec Palmerworm Sep 2020)(Citation: Reuters Taiwan BlackTech August 2020)

Goals & Targeting

Targeted Countries / Regions

TW
JP

AI Analysis

· 1 week ago

Executive Summary

BlackTech is a suspected Chinese cyber espionage group targeting organizations in East Asia and the U.S., particularly sectors like technology and finance, using custom malware and living-off-the-land tactics.

Goals & Targeting

BlackTech's primary motivation is espionage, targeting sectors with sensitive technological and strategic information. They focus on East Asian countries and the U.S., likely due to geopolitical interests and access to advanced technologies in targeted industries.

Enhanced Description

BlackTech, also known as Palmerworm, Temp.Overboard, and other aliases, has been active since at least 2013. Primarily targeting Taiwan, Japan, Hong Kong, and the U.S., this threat actor focuses on industries such as electronics, engineering, construction, and finance. They employ a mix of custom malware, dual-use tools, and living-off-the-land techniques to breach victim networks. Their activities include campaigns like Shrouded Crossbow and Waterbear, leveraging sophisticated tactics to achieve their espionage goals.

Key Capabilities

  • Custom malware
  • Dual-use tools
  • Living off the land tactics
  • Exploitation frameworks
  • Spearphishing

MITRE ATT&CK Tactics

Identity Spoofing
Credential Access
Lateral Movement
Execution
Exfiltration
Impact

ATT&CK Techniques

T1588.004
T1204.002
T1566.002
T1021.004
T1566.001
T1574.001
T1106
T1190
T1036.002
T1046

Software / Tooling

Flagpro
TSCookie
Kivars
PLEAD
Waterbear

Campaigns & Victims

BlackTech is known for prolonged campaigns targeting critical sectors. Their operational tempo includes methodical attacks with tools like PLEAD and Waterbear, often exploiting network services and using malicious files to compromise systems.

IOC Patterns

  • Spear-phishing with malicious attachments
  • Use of custom malware and dual-use tools
  • Exploitation for client execution via known techniques

Recommended Actions

  • Monitor MITRE ATT&CK techniques linked to BlackTech.
  • Implement multi-factor authentication.
  • Segment sensitive network areas.
  • Regularly update software against known vulnerabilities.
  • Train employees on phishing detection.

Suggested Tags

APT
espionage
cyber-espionage
finance-sector

Confidence Assessment

High confidence in BlackTech's APT nature and targeting patterns, though exact origins remain uncertain.

ATT&CK Techniques

Observed Data

No observed data linked yet.

References

  1. TrendMicro BlackTech June 2017 — Bermejo, L., et al. (2017, June 22). Following the Trail of BlackTech’s Cyber Espionage Campaigns. Retrieved May 5, 2020.
  2. IronNet BlackTech Oct 2021 — Demboski, M., et al. (2021, October 26). China cyber attacks: the current threat landscape. Retrieved March 25, 2022.
  3. Reuters Taiwan BlackTech August 2020 — Lee, Y. (2020, August 19). Taiwan says China behind cyberattacks on government agencies, emails. Retrieved April 6, 2022.
  4. Symantec Palmerworm Sep 2020 — Threat Intelligence. (2020, September 29). Palmerworm: Espionage Gang Targets the Media, Finance, and Other Sectors. Retrieved March 25, 2022.

Intel Summary

14

Techniques

5

Tools

3

Campaigns

1

IOCs

0

Observed Data

6

Tactics

Tags

APT
Critical Infrastructure
espionage
cyber-espionage
finance-sector

Details

MITRE ID
G0098
Type
Unknown
Resource Level
Unknown
Primary Motivation
Espionage
Country of Origin
C
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--6fe8a2a1-a1b0-4af8-953d-4babd329f8f8
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.