Overview 62 indicators
BlackTech is a suspected Chinese cyber espionage group that has primarily targeted organizations in East Asia--particularly Taiwan, Japan, and Hong Kong--and the US since at least 2013. BlackTech has used a combination of custom malware, dual-use tools, and living off the land tactics to compromise media, construction, engineering, electronics, and financial company networks.
| domain | 52 | G0098-domain.txt |
| ipv4 | 5 | G0098.json |
| url | 3 | G0098.json |
| url_path | 2 | G0098.json |
Techniques 14 ATT&CK
Open in ATT&CK Navigator → or download the layer (14 techniques, layer 4.5)
- T1021.004 SSH
- T1036.002 Right-to-Left Override
- T1046 Network Service Discovery
- T1106 Native API
- T1190 Exploit Public-Facing Application
- T1203 Exploitation for Client Execution
- T1204.001 Malicious Link
- T1204.002 Malicious File
- T1566.001 Spearphishing Attachment
- T1566.002 Spearphishing Link
- T1574.001 DLL
- T1588.002 Tool
- T1588.003 Code Signing Certificates
- T1588.004 Digital Certificates
Software 6
Principal sources 39 reports
Ranked by how many of this actor's indicators each report brought in.
- 10x.com/malwrhunterteam/status/1893295404575297…
- 10x.com/G60930953/status/1895820902400737444
- 10dmpdump.github.io/posts/Kivars
- 10app.validin.com/detail?find=212.115.54.194&type=ip4&ref…
- 10virustotal.com/gui/file/0931feef56951022c1559db77e5f01…
- 10virustotal.com/gui/file/1286aa5c73cf2c8058c52271869a57…
- 10twitter.com/nao_sec/status/1446277006690119681
- 10insight-jp.nttsecurity.com/post/102h7vx/blacktechflagpro (Japanese)
Timeline 62 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
x.com/malwrhunterteam/status/1893295404575297… · x.com/G60930953/status/1895820902400737444 · dmpdump.github.io/posts/Kivars · app.validin.com/detail?find=212.115.54.194&type=ip4&ref… · virustotal.com/gui/file/0931feef56951022c1559db77e5f01… · virustotal.com/gui/file/1286aa5c73cf2c8058c52271869a57…
domain adobeupdate.serveusers.com domain evergo.dnset.com domain fibtec.jkub.com domain herace.https443.org domain idonotknow.lflinkup.com domain idonotknow.lflinkup.net domain idonotknow.serveusers.com domain linuxhome.jkub.com domain securitycenter.kozow.com ipv4 212.115.54.194:443 -
x.com/mopisec/status/1982643509812498846 · virustotal.com/gui/ip-address/122.116.205.124/relations · virustotal.com/gui/file/a653ae9e9906c0e5a5b5ba6330e10c… · virustotal.com/gui/file/da500cacff75e224bd8ed0375463c7…
domain csp.fortinetline.com domain fortinetline.com domain microsoftvm.net domain portal.fortinetline.com domain portal.microsoftvm.net ipv4 122.116.205.124:443 ipv4 223.200.120.73:443 ipv4 61.216.119.56:443 -
x.com/TuringAlex/status/1827706865259843983 · virustotal.com/gui/ip-address/111.253.195.162/relations · virustotal.com/gui/ip-address/111.253.211.105/relations · virustotal.com/gui/file/1e1e4500b5102b130dcc6bc2ca5fef…
activate.linkblackclover.com -
trendmicro.com/en_ca/research/24/d/earth-hundun-waterb… · trendmicro.com/content/dam/trendmicro/global/en/resear…
cloudflaread.quadrantbd.com cloudsrm.gelatosg.com freeprous.bakhell.com rscvmogt.taishanlaw.com showgyella.quadrantbd.com smartclouds.gelatosg.com suitsvm003.rchitecture.org -
twitter.com/BushidoToken/status/1446602218170376199 · virustotal.com/gui/ip-address/45.32.61.175/relations · virustotal.com/gui/file/358bc9f08b34d9323bbca6eeb23f19…
ns1001.centosupdates.com updates.centosupdates.com -
virustotal.com/gui/ip-address/5.181.80.111/relations
centos1.chinabrands.xyz centos2.chinabrands.xyz -
twitter.com/nao_sec/status/1446277006690119681 · insight-jp.nttsecurity.com/post/102h7vx/blacktechflagpro (Japanese) · virustotal.com/gui/ip-address/45.32.23.140/relations · virustotal.com/gui/ip-address/45.76.184.227/relations · virustotal.com/gui/file/54e6ea47eb04634d3e87fd7787e213… · virustotal.com/gui/file/ba27ae12e6f3c2c87fd2478072dfa2… · virustotal.com/gui/file/655ca39beb2413803af099879401e6… · virustotal.com/gui/file/e197c583f57e6c560b576278233e3a… · virustotal.com/gui/file/77680fb906476f0d84e15d5032f091… · virustotal.com/gui/file/e81255ff6e0ed937603748c1442ce9…
172.104.109.217:8080 -
twitter.com/nao_sec/status/1446277006690119681 · insight-jp.nttsecurity.com/post/102h7vx/blacktechflagpro (Japanese) · virustotal.com/gui/ip-address/45.32.23.140/relations · virustotal.com/gui/ip-address/45.76.184.227/relations · virustotal.com/gui/file/54e6ea47eb04634d3e87fd7787e213… · virustotal.com/gui/file/ba27ae12e6f3c2c87fd2478072dfa2… · virustotal.com/gui/file/655ca39beb2413803af099879401e6… · virustotal.com/gui/file/e197c583f57e6c560b576278233e3a… · virustotal.com/gui/file/77680fb906476f0d84e15d5032f091… · virustotal.com/gui/file/e81255ff6e0ed937603748c1442ce9…
domain config.zapto.org domain macfee-update.serveftp.com domain microsoftonline.com.authorizeddns.net domain org.misecure.com url http://107.191.61.40 url http://139.162.87.180 url_path /index.htmld?flag= url_path /index.htmld?flagpro= -
twitter.com/nahamike01/status/1467499135171710977 · virustotal.com/gui/ip-address/103.195.150.181/relations · virustotal.com/gui/file/c2b23689ca1c57f7b7b0c2fd95bfef… · virustotal.com/gui/file/8c3df0e4d7ff0578d143785342a803…
centos.onthewifi.com redhatstate.hopto.org -
twitter.com/nao_sec/status/1446277006690119681 · insight-jp.nttsecurity.com/post/102h7vx/blacktechflagpro (Japanese) · virustotal.com/gui/ip-address/45.32.23.140/relations · virustotal.com/gui/ip-address/45.76.184.227/relations · virustotal.com/gui/file/54e6ea47eb04634d3e87fd7787e213… · virustotal.com/gui/file/ba27ae12e6f3c2c87fd2478072dfa2… · virustotal.com/gui/file/655ca39beb2413803af099879401e6… · virustotal.com/gui/file/e197c583f57e6c560b576278233e3a… · virustotal.com/gui/file/77680fb906476f0d84e15d5032f091… · virustotal.com/gui/file/e81255ff6e0ed937603748c1442ce9…
http://172.104.109.217 -
twitter.com/BushidoToken/status/1446602218170376199 · virustotal.com/gui/ip-address/45.32.61.175/relations · virustotal.com/gui/file/358bc9f08b34d9323bbca6eeb23f19…
systeminfo.centosupdates.com -
twitter.com/BushidoToken/status/1446602218170376199 · virustotal.com/gui/ip-address/45.32.61.175/relations · virustotal.com/gui/file/358bc9f08b34d9323bbca6eeb23f19…
centosupdate.dynamic-dns.net centosupdates.com centrosupdate.proxydns.com update.centosupdates.com -
unit42.paloaltonetworks.com/bendybear-shellcode-blacktech
inkeslive.com rutentw.com -
blog.jpcert.or.jp/2018/06/plead-downloader-used-by-blackt…
totalpople.info yasonbin.info -
unit42.paloaltonetworks.com/bendybear-shellcode-blacktech
web2008.rutentw.com wg1.inkeslive.com -
twitter.com/8th_grey_owl/status/1262047338006065155
harb.bbsindex.com -
otx.alienvault.com/pulse/5db0438c08e53c4d7931e3f4
update.panasocin.com -
blog.jpcert.or.jp/2018/06/plead-downloader-used-by-blackt…
panasocin.com -
welivesecurity.com/2018/07/09/certificates-stolen-taiwanes…
amazon.panasocin.com -
blog.jpcert.or.jp/2018/06/plead-downloader-used-by-blackt…
em.totalpople.info gstrap.jkub.com woc.yasonbin.info -
blog.jpcert.or.jp/2018/06/plead-downloader-used-by-blackt… · welivesecurity.com/2018/07/09/certificates-stolen-taiwanes…
office.panasocin.com -
welivesecurity.com/2018/07/09/certificates-stolen-taiwanes…
okinawas.ssl443.org
Further reading 44
- attack.mitre.org/groups/G0098
- blog.trendmicro.com/trendlabs-security-intelligence/followi…
- symantec-enterprise-blogs.security.com/blogs/threat-intelligence/palmerworm-bl…
- ironnet.com/blog/china-cyber-attacks-the-current-th…
- reuters.com/article/us-taiwan-cyber-china/taiwan-sa…
- trendmicro.com/en_ca/research/24/d/earth-hundun-waterb…
- x.com/mopisec/status/1982643509812498846
- virustotal.com/gui/file/1e1e4500b5102b130dcc6bc2ca5fef…
- virustotal.com/gui/ip-address/45.32.23.140/relations
- virustotal.com/gui/ip-address/111.253.211.105/relations
- twitter.com/nao_sec/status/1446277006690119681
- virustotal.com/gui/ip-address/111.253.195.162/relations
- blog.jpcert.or.jp/2018/06/plead-downloader-used-by-blackt…
- virustotal.com/gui/file/655ca39beb2413803af099879401e6…
- virustotal.com/gui/file/0931feef56951022c1559db77e5f01…
- virustotal.com/gui/ip-address/103.195.150.181/relations
- twitter.com/8th_grey_owl/status/1262047338006065155
- virustotal.com/gui/ip-address/45.76.184.227/relations
- twitter.com/nahamike01/status/1467499135171710977
- x.com/malwrhunterteam/status/1893295404575297…
- virustotal.com/gui/file/e81255ff6e0ed937603748c1442ce9…
- virustotal.com/gui/file/8c3df0e4d7ff0578d143785342a803…
- virustotal.com/gui/file/a653ae9e9906c0e5a5b5ba6330e10c…
- virustotal.com/gui/file/358bc9f08b34d9323bbca6eeb23f19…
- insight-jp.nttsecurity.com/post/102h7vx/blacktechflagpro (Japanese)
- unit42.paloaltonetworks.com/bendybear-shellcode-blacktech
- virustotal.com/gui/file/e197c583f57e6c560b576278233e3a…
- x.com/TuringAlex/status/1827706865259843983
- virustotal.com/gui/ip-address/45.32.61.175/relations
- virustotal.com/gui/file/da500cacff75e224bd8ed0375463c7…
- virustotal.com/gui/ip-address/5.181.80.111/relations
- virustotal.com/gui/file/c2b23689ca1c57f7b7b0c2fd95bfef…
- otx.alienvault.com/pulse/5db0438c08e53c4d7931e3f4
- welivesecurity.com/2018/07/09/certificates-stolen-taiwanes…
- virustotal.com/gui/file/1286aa5c73cf2c8058c52271869a57…
- x.com/G60930953/status/1895820902400737444
- virustotal.com/gui/ip-address/122.116.205.124/relations
- virustotal.com/gui/file/54e6ea47eb04634d3e87fd7787e213…
- trendmicro.com/content/dam/trendmicro/global/en/resear…
- twitter.com/BushidoToken/status/1446602218170376199
4 more, and the report behind every indicator, in G0098.json.