BlackTech
Also reported as Palmerworm, Canary Typhoon, T-APT-03, Red Djinn, Manga Taurus and 14 other names. Linked to China by four sources.
Reports per quarter
Techniques seen in the last two years
- T1041 4 reports reports only
- T1082 3 reports reports only
- T1106 3 reports in ATT&CK
- T1129 3 reports reports only
- T1140 3 reports reports only
- T1480 3 reports reports only
- T1005 2 reports reports only
- T1012 2 reports reports only
- T1016.001 2 reports reports only
- T1049 2 reports reports only
Show all 28 techniques Show fewer
- T1055 2 reports reports only
- T1057 2 reports reports only
- T1071.001 2 reports reports only
- T1083 2 reports reports only
- T1132.002 2 reports reports only
- T1497.003 2 reports reports only
- T1547.012 2 reports reports only
- T1573 2 reports reports only
- T1622 2 reports reports only
- T1021.006 1 report reports only
- T1027.001 1 report reports only
- T1036.005 1 report reports only
- T1059 1 report reports only
- T1059.007 1 report reports only
- T1105 1 report reports only
- T1189 1 report reports only
- T1195.001 1 report reports only
- T1574.001 1 report in ATT&CK
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
CVEs named in reports
- CVE-2008-5353
- CVE-2009-0556 KEV
- CVE-2009-0927 KEV
- CVE-2009-3129 KEV
- CVE-2009-3867
- CVE-2009-4324 KEV
- CVE-2010-0188 KEV ransomware
- CVE-2010-1424
- CVE-2010-2152
- CVE-2010-2883 KEV
- CVE-2010-3333 KEV
- CVE-2010-3915
Show all 158 CVEs Show fewer
- CVE-2010-3916
- CVE-2011-0611 KEV
- CVE-2011-1331
- CVE-2011-2462 KEV
- CVE-2011-3544 KEV
- CVE-2012-0158 KEV ransomware
- CVE-2012-1856 KEV
- CVE-2012-5687
- CVE-2013-0707
- CVE-2013-3644
- CVE-2013-3893 KEV
- CVE-2013-3900 KEV
- CVE-2013-3918 KEV
- CVE-2013-5947
- CVE-2013-5990
- CVE-2014-0810
- CVE-2014-1225
- CVE-2014-2962
- CVE-2014-4019
- CVE-2014-4113 KEV
- CVE-2014-6324 KEV
- CVE-2014-6352 KEV
- CVE-2014-7247
- CVE-2014-8361 KEV
- CVE-2014-9583
- CVE-2015-0554
- CVE-2015-1770 KEV
- CVE-2015-2545 KEV
- CVE-2015-4852 KEV
- CVE-2015-5119 KEV
- CVE-2015-7248
- CVE-2015-7254
- CVE-2016-7836 KEV
- CVE-2017-0144 KEV ransomware
- CVE-2017-0199 KEV ransomware
- CVE-2017-0261 KEV
- CVE-2017-11882 KEV ransomware
- CVE-2017-12824
- CVE-2017-15399
- CVE-2017-5638 KEV ransomware
- CVE-2017-5689 KEV
- CVE-2017-6327 KEV
- CVE-2017-7269 KEV
- CVE-2017-8291 KEV
- CVE-2018-0798 KEV
- CVE-2018-0802 KEV ransomware
- CVE-2018-13379 KEV ransomware
- CVE-2018-20250 KEV ransomware
- CVE-2018-2628 KEV
- CVE-2018-4939 KEV
- CVE-2018-6055
- CVE-2018-6789 KEV ransomware
- CVE-2018-8453 KEV ransomware
- CVE-2019-0604 KEV ransomware
- CVE-2019-0708 KEV ransomware
- CVE-2019-0797 KEV
- CVE-2019-0803 KEV ransomware
- CVE-2019-0808 KEV
- CVE-2019-0859 KEV ransomware
- CVE-2019-1040
- CVE-2019-1132 KEV
- CVE-2019-11510 KEV ransomware
- CVE-2019-11580 KEV ransomware
- CVE-2019-11707 KEV
- CVE-2019-11708 KEV
- CVE-2019-1367 KEV ransomware
- CVE-2019-13720 KEV
- CVE-2019-1458 KEV ransomware
- CVE-2019-18187 KEV
- CVE-2019-18935 KEV ransomware
- CVE-2019-19781 KEV ransomware
- CVE-2019-2215 KEV
- CVE-2019-3396 KEV ransomware
- CVE-2019-3568 KEV
- CVE-2019-5786 KEV
- CVE-2019-6225
- CVE-2019-7286 KEV
- CVE-2019-7287 KEV
- CVE-2019-8518
- CVE-2019-9489
- CVE-2020-0601 KEV
- CVE-2020-0688 KEV ransomware
- CVE-2020-10189 KEV
- CVE-2020-1350 KEV
- CVE-2020-1472 KEV ransomware
- CVE-2020-15505 KEV
- CVE-2020-1938 KEV
- CVE-2020-2021 KEV ransomware
- CVE-2020-2555 KEV
- CVE-2020-3118 KEV
- CVE-2020-5902 KEV ransomware
- CVE-2020-8193 KEV
- CVE-2020-8195 KEV
- CVE-2020-8196 KEV
- CVE-2020-8515 KEV
- CVE-2021-1472
- CVE-2021-1473
- CVE-2021-1675 KEV ransomware
- CVE-2021-1732 KEV ransomware
- CVE-2021-20021 KEV ransomware
- CVE-2021-20022 KEV ransomware
- CVE-2021-20023 KEV ransomware
- CVE-2021-20837
- CVE-2021-2135
- CVE-2021-21975 KEV ransomware
- CVE-2021-21983
- CVE-2021-22893 KEV ransomware
- CVE-2021-26084 KEV ransomware
- CVE-2021-28149
- CVE-2021-28152
- CVE-2021-28310 KEV
- CVE-2021-28482
- CVE-2021-3019
- CVE-2021-34527 KEV ransomware
- CVE-2021-40444 KEV ransomware
- CVE-2021-4104
- CVE-2021-44228 KEV ransomware
- CVE-2021-45046 KEV ransomware
- CVE-2021-45105
- CVE-2022-1040 KEV
- CVE-2022-1388 KEV ransomware
- CVE-2022-27518 KEV
- CVE-2022-30190 KEV ransomware
- CVE-2022-30333 KEV ransomware
- CVE-2022-3236 KEV
- CVE-2022-41328 KEV
- CVE-2022-42475 KEV ransomware
- CVE-2022-47966 KEV ransomware
- CVE-2023-20867 KEV
- CVE-2023-23397 KEV
- CVE-2023-26360 KEV
- CVE-2023-28461 KEV ransomware
- CVE-2023-2868 KEV
- CVE-2023-28771 KEV
- CVE-2023-3519 KEV ransomware
- CVE-2023-36033 KEV
- CVE-2023-38831 KEV ransomware
- CVE-2023-42793 KEV ransomware
- CVE-2023-46805 KEV ransomware
- CVE-2023-4966 KEV ransomware
- CVE-2023-7101 KEV
- CVE-2023-7102
- CVE-2024-21887 KEV ransomware
- CVE-2024-30051 KEV ransomware
- CVE-2024-3400 KEV ransomware
- CVE-2026-4747
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor SUNBURST (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor QakBot (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor PLEAD (Malware Family)
-
Living off the Land - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Living off the Land - Threat Group Cards: A Threat Actor Encyclopedia
-
BlackTech, Circuit Panda, Radio Panda
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor BlackTech, Circuit Panda, Radio Panda
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor REvil (Malware Family)
Show all 120 reports Show fewer
-
Waterbear Returns, Uses API Hooking to Evade Security
The original link failed its last check. Original publisher Detailsfor Waterbear Returns, Uses API Hooking to Evade Security
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor IcedID (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Ryuk (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Maze (Malware Family)
-
A Quick Look at ELF Bifrose (Part 1)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor A Quick Look at ELF Bifrose (Part 1)
-
The Rise of Earth Aughisky: Tracking the Campaigns Taidoor Started
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The Rise of Earth Aughisky: Tracking the Campaigns Taidoor Started
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor EN-BlackTech_2021
-
So Long (Go)Daddy - Tracking BlackTech Infrastructure
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor So Long (Go)Daddy - Tracking BlackTech Infrastructure
-
F5 BIG-IP Vulnerability (CVE-2022-1388) Exploited by BlackTech
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor F5 BIG-IP Vulnerability (CVE-2022-1388) Exploited by BlackTech
-
Advanced Persistent Threats (APTs)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Advanced Persistent Threats (APTs)
-
yir-cyber-threats-annex-download.pdf
The original link failed its last check. Original publisher Detailsfor yir-cyber-threats-annex-download.pdf
-
yir-cyber-threats-report-download.pdf
The original link failed its last check. Original publisher Detailsfor yir-cyber-threats-report-download.pdf
-
VMware Exposing Malware In Linux Based Multi Cloud Environments
The original link failed its last check. Original publisher Detailsfor VMware Exposing Malware In Linux Based Multi Cloud Environments
-
Flagpro- The new malware used by BlackTech
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Flagpro- The new malware used by BlackTech
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor More Flagpro, More Problems
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor BlackTech, an East Asian hacking group, has launched attacks in sectors such as finance and education
-
Malware Flagpro used by targeted attack group BlackTech
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Malware Flagpro used by targeted attack group BlackTech
-
Malware Gh0stTimes Used by BlackTech - JPCERT_CC Eyes _ JPCERT Coordination Center official Blog
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Malware Gh0stTimes Used by BlackTech - JPCERT_CC Eyes _ JPCERT Coordination Center official Blog
-
Malware Gh0stTimes Used by BlackTech
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Malware Gh0stTimes Used by BlackTech
-
Advanced Persistent Threats (APTs)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Advanced Persistent Threats (APTs)
-
APT Threat Landscape of Taiwan in 2020
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT Threat Landscape of Taiwan in 2020
-
APT10: Tracking down the stealth activity of the A41APT campaign
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT10: Tracking down the stealth activity of the A41APT campaign
-
A41APT case ~Analysis of the Stealth APT Campaign Threatening Japan
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor A41APT case ~Analysis of the Stealth APT Campaign Threatening Japan
-
The_CrowdStrike_2021_Global_Threat_Report
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The_CrowdStrike_2021_Global_Threat_Report
-
BlackTech Updates Elf-Plead Backdoor
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor BlackTech Updates Elf-Plead Backdoor
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor unit42.paloaltonetworks.com-BendyBear Novel Chinese Shellcode Linked With Cyber Espionage Group BlackTech
-
China cyber attacks- the current threat landscape
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor China cyber attacks- the current threat landscape
-
ELF_PLEAD - Linux Malware Used by BlackTech
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor ELF_PLEAD - Linux Malware Used by BlackTech
-
Palmerworm_ Espionage Gang Targets the Media, Finance, and Other Sectors _ Symantec Blogs
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Palmerworm_ Espionage Gang Targets the Media, Finance, and Other Sectors _ Symantec Blogs
-
Palmerworm- Espionage Gang Targets the Media, Finance, and Other Sectors
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Palmerworm- Espionage Gang Targets the Media, Finance, and Other Sectors
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor 調查局 08-19 公布中國對台灣政府機關駭侵事件說明
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor P01_P10_eng
-
mpressioncss_ta_report_2019_4.pdf
The original link failed its last check. Original publisher Detailsfor mpressioncss_ta_report_2019_4.pdf
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor mpressioncss_ta_report_2019_4
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor PoshC2_APT_jp
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor 中國駭客 HUAPI 的惡意後門程式 BiFrost 分析
-
The original link failed its last check. Original publisher Detailsfor 정상 인증서에 숨은 섀도 포스, 7년간의 행적 드러나
-
ELF_TSCookie - Linux Malware Used by BlackTech
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor ELF_TSCookie - Linux Malware Used by BlackTech
-
2020.02.22_APT_threat_report_2019_CN_version
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 2020.02.22_APT_threat_report_2019_CN_version
-
Cyber Threat Landscape in Japan – Revealing Threat in the Shadow
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cyber Threat Landscape in Japan – Revealing Threat in the Shadow
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor [CB19] Cyber Threat Landscape in Japan – Revealing Threat in the Shadow by Chi En Shen (Ashley) Oleg Bondarenko
-
Waterbear is Back, Uses API Hooking to Evade Security Product Detection
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Waterbear is Back, Uses API Hooking to Evade Security Product Detection
-
Waterbear Returns, Uses API Hooking to Evade Security
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Waterbear Returns, Uses API Hooking to Evade Security
-
IconDown – Downloader Used by BlackTech
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor IconDown – Downloader Used by BlackTech
-
APT cases exploiting vulnerabilities in region‑specific software
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT cases exploiting vulnerabilities in region‑specific software
-
Malware Used by BlackTech after Network Intrusion
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Malware Used by BlackTech after Network Intrusion
-
Bug in Malware “TSCookie” - Fails to Read Configuration - (Update)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Bug in Malware “TSCookie” - Fails to Read Configuration - (Update)
-
Plead malware distributed via MitM attacks at router level, misusing ASUS WebStorage
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Plead malware distributed via MitM attacks at router level, misusing ASUS WebStorage
-
mpressioncss_ta_report_2019.pdf
The original link failed its last check. Original publisher Detailsfor mpressioncss_ta_report_2019.pdf
-
Bug in Malware “TSCookie” - Fails to Read Configuration
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Bug in Malware “TSCookie” - Fails to Read Configuration
-
Certificates stolen from Taiwanese tech‑companies misused in Plead malware campaign
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Certificates stolen from Taiwanese tech‑companies misused in Plead malware campaign
-
Stolen digital certificates misused in Plead malware campaign discovered
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Stolen digital certificates misused in Plead malware campaign discovered
-
Analysis of BlackTech's latest APT attack
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Analysis of BlackTech's latest APT attack
-
Analysis of BlackTech's latest APT attack
The original link failed its last check. Detailsfor Analysis of BlackTech's latest APT attack
-
Advanced Persistent Threat Groups
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Advanced Persistent Threat Groups
-
ChessMaster Makes its Move: A Look into its Arsenal
The original link failed its last check. Original publisher Detailsfor ChessMaster Makes its Move: A Look into its Arsenal
-
The Trail of BlackTech’s Cyber Espionage Campaigns
The original link failed its last check. Original publisher Detailsfor The Trail of BlackTech’s Cyber Espionage Campaigns
-
The Trail of BlackTech’s Cyber Espionage Campaigns
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Trail of BlackTech’s Cyber Espionage Campaigns
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor TrendLabs Security Intelligence BlogFollowing the Trail of BlackTech’s Cyber Espionage Campaigns - TrendLabs Security Intelligence Blog
-
Following the Trail of BlackTech’s Cyber Espionage Campaigns
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Following the Trail of BlackTech’s Cyber Espionage Campaigns
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor TrendLabs Security Intelligence BlogFollowing the Trail of BlackTech’s Cyber Espionage Campaigns - TrendLabs Security Intelligence Blog
-
The Four Element Sword Engagement
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor The Four Element Sword Engagement
-
Shrouded Crossbow Creators Behind BIFROSE for UNIX
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Shrouded Crossbow Creators Behind BIFROSE for UNIX
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
Newest first. Details opens the report in Explore.