ATT&CKGroupsBlackTech

BlackTech

G0098

Threat group.View on attack.mitre.org

About this group

BlackTech is a suspected Chinese cyber espionage group that has primarily targeted organizations in East Asia--particularly Taiwan, Japan, and Hong Kong--and the US since at least 2013. BlackTech has used a combination of custom malware, dual-use tools, and living off the land tactics to compromise media, construction, engineering, electronics, and financial company networks.

Techniques used14

Procedure examples14

TechniqueProcedure example
T1021.004
SSH

BlackTech has used Putty for remote access.

T1036.002
Right-to-Left Override

BlackTech has used right-to-left-override to obfuscate the filenames of malicious e-mail attachments.

T1046
Network Service Discovery

BlackTech has used the SNScan tool to find other potential targets on victim networks.

T1106
Native API

BlackTech has used built-in API functions.

T1190
Exploit Public-Facing Application

BlackTech has exploited a buffer overflow vulnerability in Microsoft Internet Information Services (IIS) 6.0, CVE-2017-7269, in order to establish a new HTTP or command and control (C2) server.

T1203
Exploitation for Client Execution

BlackTech has exploited multiple vulnerabilities for execution, including Microsoft Office vulnerabilities CVE-2012-0158, CVE-2014-6352, CVE-2017-0199, and Adobe Flash CVE-2015-5119.

T1204.001
Malicious Link

BlackTech has used e-mails with malicious links to lure victims into installing malware.

T1204.002
Malicious File

BlackTech has used e-mails with malicious documents to lure victims into installing malware.

T1566.001
Spearphishing Attachment

BlackTech has used spearphishing e-mails with malicious password-protected archived files (ZIP or RAR) to deliver malware.

T1566.002
Spearphishing Link

BlackTech has used spearphishing e-mails with links to cloud services to deliver malware.

T1574.001
DLL

BlackTech has used DLL side loading by giving DLLs hardcoded names and placing them in searched directories.

T1588.002
Tool

BlackTech has obtained and used tools such as Putty, SNScan, and PsExec for its operations.

T1588.003
Code Signing Certificates

BlackTech has used stolen code-signing certificates for its malicious payloads.

T1588.004
Digital Certificates

BlackTech has used valid, stolen digital certificates for some of their malware and tools.

Software6

Campaigns0

None recorded.

References3

  1. Reuters Taiwan BlackTech August 2020 Open source
    Lee, Y. (2020, August 19). Taiwan says China behind cyberattacks on government agencies, emails. Retrieved April 6, 2022.
  2. Symantec Palmerworm Sep 2020 Open source
    Threat Intelligence. (2020, September 29). Palmerworm: Espionage Gang Targets the Media, Finance, and Other Sectors. Retrieved March 25, 2022.
  3. TrendMicro BlackTech June 2017 Open source
    Bermejo, L., et al. (2017, June 22). Following the Trail of BlackTech’s Cyber Espionage Campaigns. Retrieved May 5, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.