BlackTech Escalates Attacks on Japanese Organizations: Spear-Phishing, Exchange Exploitation, and a Custom Malware Factory

A threat intelligence report from NTT Security Holdings Japan SOC documents a surge in targeted attacks by BlackTech — also tracked as Palmerworm, Red Djinn, Earth Hundun, and HUAPI — against Japanese organizations across the telecommunications, defense, and mass media sectors, with the group's activity sharply accelerating around 2020. Active since at least 2012, BlackTech combines spear-phishing, server vulnerability exploitation, and a continuously expanding custom malware arsenal in campaigns designed to exfiltrate sensitive information from high-value targets in Eastern Asia, particularly Taiwan and Japan.

Initial Access: Spear-Phishing and Server Exploitation

BlackTech's intrusions enter through two primary vectors. The majority of observed attacks begin with highly crafted spear-phishing emails impersonating business partners, delivering either executable files with double extensions or malicious Microsoft Excel files in XLSM format — sometimes packaged in password-protected RAR archives with the password embedded in the email body. NTT analysts noted that in some cases, BlackTech incorporated actual internal documents from target organizations into the lure, raising the social engineering sophistication significantly above commodity phishing. The consistency of macro code across observed XLSM files (tracked internally as LAMICE) suggests a single automated tool generates these lure documents.

The secondary vector is server-side vulnerability exploitation, particularly against Microsoft Exchange Server, with successful exploitation leading to malware execution, environmental reconnaissance, and lateral movement deeper into the target organization. NTT's research aligns with JPCERT/CC reporting that BlackTech's C2 infrastructure hosted tools capable of exploiting a range of server vulnerabilities.

A Recurring Pattern: Overseas Branch to Headquarters

A distinctive operational pattern observed repeatedly by NTT's SOC is BlackTech establishing an initial foothold in the overseas branch office of a Japanese company before pivoting into the mission-critical systems at headquarters. This approach exploits the often weaker security posture of remote and international offices while providing a trusted network position from which to move laterally into the core corporate environment — a technique that highlights the importance of consistent security controls across all organizational locations regardless of geography.

Malware Arsenal: Flagpro, TSCookie, PLEAD, and More

BlackTech deploys a layered malware toolkit combining publicly available tools with proprietary implants continuously under development. Key components include:

Continuous Tooling Development as an Indicator of Sustained Intent

NTT's assessment emphasizes that BlackTech's active development of new malware families — not merely reusing existing tools — signals a well-resourced, operationally active group with sustained intent against Japanese and Taiwanese targets. Organizations in the telecommunications, defense, and media sectors in Eastern Asia should treat both their headquarters and all remote offices as targets, implementing equivalent security monitoring and controls across all locations to close the lateral movement pathway BlackTech has repeatedly exploited.

Read the full analysis on IntelFusions