BlackTech — APT Profile
BlackTech is a suspected Chinese cyber espionage group that has primarily targeted organizations in East Asia--particularly Taiwan, Japan, and Hong Kong--and the US since at least 2013. BlackTech has used a combination of custom malware, dual-use tools, and living off the land tactics to compromise media, construction, engineering, electronics, and financial company networks.Description reproduced from MITRE ATT&CK. © The MITRE Corporation, reproduced and distributed with permission.
Also tracked as
Palmerworm, CIRCUIT PANDA, Temp.Overboard, HUAPI, G0098, T-APT-03, Manga Taurus, Red Djinn, Earth Hundun, Canary Typhoon, Mobwork, CAVERN CASTLE
IntelFusions coverage (2)
- Suspected China Group Uses Microsoft-Signed Driver to Disable Security Software in Japan 2026-06-17 · Nation-State
- BlackTech Escalates Attacks on Japanese Organizations: Spear-Phishing, Exchange Exploitation, and a Custom Malware Factory 2026-02-16 · Nation-State
Tools & malware
- Flagpro Backdoor
- Kivars Backdoor
- PLEAD Backdoor
- PsExec Remote Execution
- TSCookie Backdoor
- Waterbear Backdoor
Vendor research
- Following the Trail of BlackTech’s Cyber Espionage Campaigns TrendMicro
- China cyber attacks: the current threat landscape IronNet
- Taiwan says China behind cyberattacks on government agencies, emails Reuters
- Palmerworm: Espionage Gang Targets the Media, Finance, and Other Sectors Symantec