A threat intelligence report from NTT Security Holdings Japan SOC documents a surge in targeted attacks by BlackTech — also tracked as Palmerworm, Red Djinn, Earth Hundun, and HUAPI — against Japanese organizations across the telecommunications, defense, and mass media sectors, with the group's activity sharply accelerating around 2020. Active since at least 2012, BlackTech combines spear-phishing, server vulnerability exploitation, and a continuously expanding custom malware arsenal in campaigns designed to exfiltrate sensitive information from high-value targets in Eastern Asia, particularly Taiwan and Japan.
Initial Access: Spear-Phishing and Server Exploitation
BlackTech's intrusions enter through two primary vectors. The majority of observed attacks begin with highly crafted spear-phishing emails impersonating business partners, delivering either executable files with double extensions or malicious Microsoft Excel files in XLSM format — sometimes packaged in password-protected RAR archives with the password embedded in the email body. NTT analysts noted that in some cases, BlackTech incorporated actual internal documents from target organizations into the lure, raising the social engineering sophistication significantly above commodity phishing. The consistency of macro code across observed XLSM files (tracked internally as LAMICE) suggests a single automated tool generates these lure documents.
The secondary vector is server-side vulnerability exploitation, particularly against Microsoft Exchange Server, with successful exploitation leading to malware execution, environmental reconnaissance, and lateral movement deeper into the target organization. NTT's research aligns with JPCERT/CC reporting that BlackTech's C2 infrastructure hosted tools capable of exploiting a range of server vulnerabilities.
A Recurring Pattern: Overseas Branch to Headquarters
A distinctive operational pattern observed repeatedly by NTT's SOC is BlackTech establishing an initial foothold in the overseas branch office of a Japanese company before pivoting into the mission-critical systems at headquarters. This approach exploits the often weaker security posture of remote and international offices while providing a trusted network position from which to move laterally into the core corporate environment — a technique that highlights the importance of consistent security controls across all organizational locations regardless of geography.
Malware Arsenal: Flagpro, TSCookie, PLEAD, and More
BlackTech deploys a layered malware toolkit combining publicly available tools with proprietary implants continuously under development. Key components include:
- Flagpro: An initial-phase reconnaissance and loader tool, with v1.0 observed from October 2020 and v2.0 (using the MFC library) from July 2021. Flagpro downloads and executes further malware, runs OS commands and returns results, and collects and exfiltrates Windows authentication credentials. It uses Internet Explorer's COM object IWebBrowser2 interface for C2 communication — an unusual implementation designed to blend with legitimate browser traffic.
- TSCookie and PLEAD: Self-developed backdoors that form the core of BlackTech's persistent access capability.
- Bifrost and Gh0st RAT: Publicly available RATs deployed across both Windows (PE) and Linux (ELF) environments, demonstrating the group's cross-platform targeting capability.
Continuous Tooling Development as an Indicator of Sustained Intent
NTT's assessment emphasizes that BlackTech's active development of new malware families — not merely reusing existing tools — signals a well-resourced, operationally active group with sustained intent against Japanese and Taiwanese targets. Organizations in the telecommunications, defense, and media sectors in Eastern Asia should treat both their headquarters and all remote offices as targets, implementing equivalent security monitoring and controls across all locations to close the lateral movement pathway BlackTech has repeatedly exploited.