BlackTech

MITRE ATT&CK: G0098 View on attack.mitre.org

Aliases: Palmerworm, CIRCUIT PANDA, Temp.Overboard, HUAPI, T-APT-03, Manga Taurus, Red Djinn, Earth Hundun, Canary Typhoon, Mobwork, BlackTech, APT24

First seen
2013-01-01 00:00:00
Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Related IoCs
9 (9 malicious)
Last IoC activity
2026-08-26 07:50:49
Profile updated
2026-07-07 11:47:55

Targeted industries: media-and-entertainment financial-services technology-and-telecommunications manufacturing

Targeted regions: country_code:tw country_code:jp country_code:hk country_code:us

Context

BlackTech is a suspected Chinese cyber espionage group that has primarily targeted organizations in East Asia--particularly Taiwan, Japan, and Hong Kong--and the US since at least 2013. BlackTech has used a combination of custom malware, dual-use tools, and living off the land tactics to compromise media, construction, engineering, electronics, and financial company networks.

Recent IoC activity

9 malicious indicators in Maltiverse are attributed to BlackTech (G0098). The 9 most recently updated:

Detection coverage

  • 5 YARA rules
  • 245 Sigma rules

Malware & tools used

  • Malicious Link (attack-pattern)
  • Code Signing Certificates (attack-pattern)
  • Network Service Discovery (attack-pattern)
  • Tool (attack-pattern)
  • Exploit Public-Facing Application (attack-pattern)
  • SSH (attack-pattern)
  • Native API (attack-pattern)
  • Exploitation for Client Execution (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Right-to-Left Override (attack-pattern)
  • DLL (attack-pattern)
  • Malicious File (attack-pattern)
  • Digital Certificates (attack-pattern)
  • Spearphishing Link (attack-pattern)
  • Flagpro (malware)
  • TSCookie (malware)
  • Kivars (malware)
  • PLEAD (malware)
  • Waterbear (malware)
  • PsExec (malware)

Reports & references

  • cloud.google.com — Updated Cyber Threat Actor Naming System (report)
  • pwc.com — Yir Cyber Threats Report Download (report)
  • pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
  • CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
  • Trend Micro — Following Trail Blacktech Cyber Espionage Campaigns (report)
  • ESET — Certificates Stolen Taiwanese Tech Companies Plead Malware Campaign (report)
  • ESET — Plead Malware Mitm Asus Webstorage (report)
  • slideshare.net — Cb19 Cyber Threat Landscape In Japan Revealing Threat In The Shadow By Chi En Shen Ashley Oleg Bondarenko (report)
  • Broadcom/Symantec — Palmerworm Blacktech Espionage Apt (report)
  • Palo Alto Unit 42 — Mangataurus (report)
  • Trend Micro — Earth Hundun Waterbear Deuterbear (report)
  • blogs.jpcert.or.jp — Jsac2022Report1 (report)
  • raw.githubusercontent.com — Microsoftmapping (report)
  • MITRE ATT&CK — G0098 (report)
  • ironnet.com — China Cyber Attacks The Current Threat Landscape (report)
  • reuters.com — Taiwan Says China Behind Cyberattacks On Government Agencies Emails Iduskcn25F0Jk (report)

External references