Also known as: Palmerworm, CIRCUIT PANDA, Temp.Overboard, HUAPI, G0098, T-APT-03, Manga Taurus, Red Djinn, Earth Hundun, Canary Typhoon, Mobwork, CAVERN CASTLE
BlackTech is a suspected Chinese cyber espionage group that has primarily targeted organizations in East Asia--particularly Taiwan, Japan, and Hong Kong--and the US since at least 2013. BlackTech has used a combination of custom malware, dual-use tools, and living off the land tactics to compromise media, construction, engineering, electronics, and financial company networks.(Citation: TrendMicro BlackTech June 2017)(Citation: Symantec Palmerworm Sep 2020)(Citation: Reuters Taiwan BlackTech August 2020)
Targeted Countries / Regions
Executive Summary
BlackTech is a suspected Chinese cyber espionage group targeting organizations in East Asia and the U.S., particularly sectors like technology and finance, using custom malware and living-off-the-land tactics.
Goals & Targeting
BlackTech's primary motivation is espionage, targeting sectors with sensitive technological and strategic information. They focus on East Asian countries and the U.S., likely due to geopolitical interests and access to advanced technologies in targeted industries.
Enhanced Description
BlackTech, also known as Palmerworm, Temp.Overboard, and other aliases, has been active since at least 2013. Primarily targeting Taiwan, Japan, Hong Kong, and the U.S., this threat actor focuses on industries such as electronics, engineering, construction, and finance. They employ a mix of custom malware, dual-use tools, and living-off-the-land techniques to breach victim networks. Their activities include campaigns like Shrouded Crossbow and Waterbear, leveraging sophisticated tactics to achieve their espionage goals.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
BlackTech is known for prolonged campaigns targeting critical sectors. Their operational tempo includes methodical attacks with tools like PLEAD and Waterbear, often exploiting network services and using malicious files to compromise systems.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in BlackTech's APT nature and targeting patterns, though exact origins remain uncertain.
No observed data linked yet.
14
Techniques
5
Tools
3
Campaigns
1
IOCs
0
Observed Data
6
Tactics