Also known as: Topgear, Comnie, BLACKGEAR
**Targets:** Japan, Taiwan, South Korea **Toolset/Malware:** Protux, Eliriks **Notes:** Dates back to 2008
Targeted Countries / Regions
Executive Summary
Blackgear, a suspected nation-state threat actor with ties to espionage activities, primarily targets South Korea, Taiwan, and Japan. The group utilizes custom tools such as Protux and Eliriks, suggesting advanced capabilities. Despite its historical activity dating back to 2008, limited information on specific tactics and campaigns poses challenges in comprehensive threat assessment.
Goals & Targeting
Blackgear's strategic objectives likely center around intelligence gathering to support state-sponsored activities. The targeting of South Korea, Taiwan, and Japan may reflect geopolitical priorities or sector-specific interests, such as government agencies, technology, or defense industries. This aligns with common nation-state espionage goals.
Enhanced Description
Blackgear is a nation-state actor known for targeting the Asia-Pacific region, specifically focusing on South Korea, Taiwan, and Japan. The group's primary motivation appears to be espionage, aiming to collect sensitive information from targeted sectors. Blackgear has been associated with the malware tools Protux and Eliriks, indicating a capability for developing custom malicious software. The actor's longevity since 2008 suggests persistent and possibly evolving tactics over time. While exact campaign details are sparse, the focus on specific countries implies strategic targeting aligned with national or regional interests.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Blackgear's campaigns likely involve prolonged and targeted operations, leveraging custom tools to gain unauthorized access. Limited details on specific campaigns suggest a focus on stealth and long-term goals, possibly avoiding high-profile incidents to maintain operational security.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate confidence in the nation-state designation and malware associations. Limited data on specific campaigns, TTPs, and exact targets reduces certainty.
0
Techniques
2
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics