BlackTech
MITRE ATT&CK: G0098 View on attack.mitre.org
Aliases: Palmerworm, CIRCUIT PANDA, Temp.Overboard, HUAPI, T-APT-03, Manga Taurus, Red Djinn, Earth Hundun, Canary Typhoon, Mobwork, BlackTech, APT24
- First seen
- 2013-01-01 00:00:00
- Origin
- CN
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Related IoCs
- 9 (9 malicious)
- Last IoC activity
- 2026-08-26 07:50:49
- Profile updated
- 2026-07-07 11:47:55
Targeted industries: media-and-entertainment financial-services technology-and-telecommunications manufacturing
Targeted regions: country_code:tw country_code:jp country_code:hk country_code:us
Context
BlackTech is a suspected Chinese cyber espionage group that has primarily targeted organizations in East Asia--particularly Taiwan, Japan, and Hong Kong--and the US since at least 2013. BlackTech has used a combination of custom malware, dual-use tools, and living off the land tactics to compromise media, construction, engineering, electronics, and financial company networks.
Recent IoC activity
9 malicious indicators in Maltiverse are attributed to BlackTech (G0098). The 9 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | OTX_a26df4f62ada084a596bf0f603691bc9c02024be98abec4a9872f0ff0085f940 | 2026-08-26 | 2 |
| file sample | Asus Webstorage Upate.exe | 2026-07-08 | 2 |
| file sample | f6494698448cdaf6ec0ed7b3555521e75fac5189fa3c89ba7b2ad492188005b4 | 2026-03-03 | 1 |
| file sample | bc2c8cc9896cdd5816509f43cb5dca7433198251d754a997a70db7e8ed5cca40 | 2026-03-03 | 1 |
| file sample | eec3f761f7eabe9ed569f39e896be24c9bbb8861b15dbde1b3d539505cd9dd8d | 2026-03-03 | 1 |
| file sample | 6bf301b26a919f86655e4ccb20237cc3b6b6888f258d96aac4d62df7980e51a5 | 2026-03-03 | 1 |
| file sample | 2e789fc5aa1318d0286264d70b2ececa15664689efa4f47c485d84df55231ac4 | 2026-03-03 | 1 |
| file sample | 23f554cc5bea9d4ccd62b0bbccaa4599f225ebce4ad956a576cc1a9b2a73dc15 | 2026-03-03 | 1 |
| file sample | 2ddb2030ab3373b9438102b541aa4623b7dfee972850dcef05742ecbe8982e22 | 2026-03-03 | 1 |
Detection coverage
- 5 YARA rules
- 245 Sigma rules
Malware & tools used
- Malicious Link (attack-pattern)
- Code Signing Certificates (attack-pattern)
- Network Service Discovery (attack-pattern)
- Tool (attack-pattern)
- Exploit Public-Facing Application (attack-pattern)
- SSH (attack-pattern)
- Native API (attack-pattern)
- Exploitation for Client Execution (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Right-to-Left Override (attack-pattern)
- DLL (attack-pattern)
- Malicious File (attack-pattern)
- Digital Certificates (attack-pattern)
- Spearphishing Link (attack-pattern)
- Flagpro (malware)
- TSCookie (malware)
- Kivars (malware)
- PLEAD (malware)
- Waterbear (malware)
- PsExec (malware)
Reports & references
- cloud.google.com — Updated Cyber Threat Actor Naming System (report)
- pwc.com — Yir Cyber Threats Report Download (report)
- pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
- CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
- Trend Micro — Following Trail Blacktech Cyber Espionage Campaigns (report)
- ESET — Certificates Stolen Taiwanese Tech Companies Plead Malware Campaign (report)
- ESET — Plead Malware Mitm Asus Webstorage (report)
- slideshare.net — Cb19 Cyber Threat Landscape In Japan Revealing Threat In The Shadow By Chi En Shen Ashley Oleg Bondarenko (report)
- Broadcom/Symantec — Palmerworm Blacktech Espionage Apt (report)
- Palo Alto Unit 42 — Mangataurus (report)
- Trend Micro — Earth Hundun Waterbear Deuterbear (report)
- blogs.jpcert.or.jp — Jsac2022Report1 (report)
- raw.githubusercontent.com — Microsoftmapping (report)
- MITRE ATT&CK — G0098 (report)
- ironnet.com — China Cyber Attacks The Current Threat Landscape (report)
- reuters.com — Taiwan Says China Behind Cyberattacks On Government Agencies Emails Iduskcn25F0Jk (report)
External references
- mitre-attack — G0098
- Palmerworm
- TrendMicro BlackTech June 2017
- IronNet BlackTech Oct 2021
- Reuters Taiwan BlackTech August 2020
- Symantec Palmerworm Sep 2020
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy