Blackwood
- First seen
- 2018-01-01 00:00:00
- Origin
- CN
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Last IoC activity
- 2026-07-16 17:56:14
- Profile updated
- 2026-07-07 12:12:14
Targeted industries: government-and-public-sector technology-and-telecommunications defense-and-aerospace
Targeted regions: country_code:cn country_code:jp country_code:gb
Context
Blackwood is a China-aligned APT group that has been active since at least 2018. They primarily engage in cyberespionage operations targeting individuals and companies in China, Japan, and the United Kingdom. Blackwood utilizes sophisticated techniques such as adversary-in-the-middle attacks to deliver their custom implant, NSPX30, through updates of legitimate software. They also have the capability to hide the location of their command and control servers by intercepting traffic generated by the implant.
Reports & references
- ESET — Nspx30 Sophisticated Aitm Enabled Implant Evolving Since 2005 (report)
- blog.sonicwall.com — Blackwood Apt Group Has A New Dll Loader (report)