Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Blackgear

Also known as: Topgear, Comnie, BLACKGEAR

Description

**Targets:** Japan, Taiwan, South Korea **Toolset/Malware:** Protux, Eliriks **Notes:** Dates back to 2008

Goals & Targeting

Targeted Countries / Regions

TW
KR
JP

AI Analysis

· 1 week ago

Executive Summary

Blackgear, a suspected nation-state threat actor with ties to espionage activities, primarily targets South Korea, Taiwan, and Japan. The group utilizes custom tools such as Protux and Eliriks, suggesting advanced capabilities. Despite its historical activity dating back to 2008, limited information on specific tactics and campaigns poses challenges in comprehensive threat assessment.

Goals & Targeting

Blackgear's strategic objectives likely center around intelligence gathering to support state-sponsored activities. The targeting of South Korea, Taiwan, and Japan may reflect geopolitical priorities or sector-specific interests, such as government agencies, technology, or defense industries. This aligns with common nation-state espionage goals.

Enhanced Description

Blackgear is a nation-state actor known for targeting the Asia-Pacific region, specifically focusing on South Korea, Taiwan, and Japan. The group's primary motivation appears to be espionage, aiming to collect sensitive information from targeted sectors. Blackgear has been associated with the malware tools Protux and Eliriks, indicating a capability for developing custom malicious software. The actor's longevity since 2008 suggests persistent and possibly evolving tactics over time. While exact campaign details are sparse, the focus on specific countries implies strategic targeting aligned with national or regional interests.

Key Capabilities

  • Development and use of custom malware (Protux, Eliriks)
  • Advanced persistent threat (APT) tactics
  • Possibly long-term, stealthy campaigns

MITRE ATT&CK Tactics

Espionage
Initial Access
Defense Evasion
Network Operations

ATT&CK Techniques

T1059
T1233
T1815
T1087

Software / Tooling

Protux
Eliriks

Campaigns & Victims

Blackgear's campaigns likely involve prolonged and targeted operations, leveraging custom tools to gain unauthorized access. Limited details on specific campaigns suggest a focus on stealth and long-term goals, possibly avoiding high-profile incidents to maintain operational security.

IOC Patterns

  • Spear-phishing emails with malicious attachments
  • Network traffic anomalies associated with Protux/Eliriks
  • Unusual domain name registration patterns linked to the malware

Recommended Actions

  • Monitor for spear-phishing attempts and suspicious email activity.
  • Implement strong authentication measures for sensitive systems.
  • Regularly update and patch software to mitigate known vulnerabilities.

Suggested Tags

nation-state
APT
espionage
South Korea
Japan

Confidence Assessment

Moderate confidence in the nation-state designation and malware associations. Limited data on specific campaigns, TTPs, and exact targets reduces certainty.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

2

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
nation-state
espionage
South Korea
Japan

Details

Type
Nation-State
Resource Level
Unknown
Primary Motivation
Espionage
Country of Origin
C
Confidence
70%
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.