← All actors Recent activity

BlackTech G0098

BLACKTECH · EARTHHUNDUN

Indicators
62
Source reports
39
Activity span
not dated
Newest indicator
unknown
Upstream change
2026-01-02
20182026

Overview 62 indicators

BlackTech is a suspected Chinese cyber espionage group that has primarily targeted organizations in East Asia--particularly Taiwan, Japan, and Hong Kong--and the US since at least 2013. BlackTech has used a combination of custom malware, dual-use tools, and living off the land tactics to compromise media, construction, engineering, electronics, and financial company networks.

domain52G0098-domain.txt
ipv45G0098.json
url3G0098.json
url_path2G0098.json

Techniques 14 ATT&CK

Open in ATT&CK Navigator → or download the layer (14 techniques, layer 4.5)

Software 6

Principal sources 39 reports

Ranked by how many of this actor's indicators each report brought in.

Timeline 62 indicators

Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.

  1. or earlier 9 domain, 1 ipv4this year

    x.com/malwrhunterteam/status/1893295404575297… · x.com/G60930953/status/1895820902400737444 · dmpdump.github.io/posts/Kivars · app.validin.com/detail?find=212.115.54.194&type=ip4&ref… · virustotal.com/gui/file/0931feef56951022c1559db77e5f01… · virustotal.com/gui/file/1286aa5c73cf2c8058c52271869a57…

    domainadobeupdate.serveusers.com
    domainevergo.dnset.com
    domainfibtec.jkub.com
    domainherace.https443.org
    domainidonotknow.lflinkup.com
    domainidonotknow.lflinkup.net
    domainidonotknow.serveusers.com
    domainlinuxhome.jkub.com
    domainsecuritycenter.kozow.com
    ipv4212.115.54.194:443

  2. or earlier 5 domain, 3 ipv4this year

    x.com/mopisec/status/1982643509812498846 · virustotal.com/gui/ip-address/122.116.205.124/relations · virustotal.com/gui/file/a653ae9e9906c0e5a5b5ba6330e10c… · virustotal.com/gui/file/da500cacff75e224bd8ed0375463c7…

    domaincsp.fortinetline.com
    domainfortinetline.com
    domainmicrosoftvm.net
    domainportal.fortinetline.com
    domainportal.microsoftvm.net
    ipv4122.116.205.124:443
    ipv4223.200.120.73:443
    ipv461.216.119.56:443

  3. 1 domain2 yrs ago

    x.com/TuringAlex/status/1827706865259843983 · virustotal.com/gui/ip-address/111.253.195.162/relations · virustotal.com/gui/ip-address/111.253.211.105/relations · virustotal.com/gui/file/1e1e4500b5102b130dcc6bc2ca5fef…

    activate.linkblackclover.com

  4. 7 domain2 yrs ago

    trendmicro.com/en_ca/research/24/d/earth-hundun-waterb… · trendmicro.com/content/dam/trendmicro/global/en/resear…

    cloudflaread.quadrantbd.com
    cloudsrm.gelatosg.com
    freeprous.bakhell.com
    rscvmogt.taishanlaw.com
    showgyella.quadrantbd.com
    smartclouds.gelatosg.com
    suitsvm003.rchitecture.org

  5. 2 domain3 yrs ago

    twitter.com/BushidoToken/status/1446602218170376199 · virustotal.com/gui/ip-address/45.32.61.175/relations · virustotal.com/gui/file/358bc9f08b34d9323bbca6eeb23f19…

    ns1001.centosupdates.com
    updates.centosupdates.com

  6. 2 domain3 yrs ago

    virustotal.com/gui/ip-address/5.181.80.111/relations

    centos1.chinabrands.xyz
    centos2.chinabrands.xyz

  7. 1 ipv44 yrs ago

    twitter.com/nao_sec/status/1446277006690119681 · insight-jp.nttsecurity.com/post/102h7vx/blacktechflagpro (Japanese) · virustotal.com/gui/ip-address/45.32.23.140/relations · virustotal.com/gui/ip-address/45.76.184.227/relations · virustotal.com/gui/file/54e6ea47eb04634d3e87fd7787e213… · virustotal.com/gui/file/ba27ae12e6f3c2c87fd2478072dfa2… · virustotal.com/gui/file/655ca39beb2413803af099879401e6… · virustotal.com/gui/file/e197c583f57e6c560b576278233e3a… · virustotal.com/gui/file/77680fb906476f0d84e15d5032f091… · virustotal.com/gui/file/e81255ff6e0ed937603748c1442ce9…

    172.104.109.217:8080

  8. 4 domain, 2 url, 2 url_path5 yrs ago

    twitter.com/nao_sec/status/1446277006690119681 · insight-jp.nttsecurity.com/post/102h7vx/blacktechflagpro (Japanese) · virustotal.com/gui/ip-address/45.32.23.140/relations · virustotal.com/gui/ip-address/45.76.184.227/relations · virustotal.com/gui/file/54e6ea47eb04634d3e87fd7787e213… · virustotal.com/gui/file/ba27ae12e6f3c2c87fd2478072dfa2… · virustotal.com/gui/file/655ca39beb2413803af099879401e6… · virustotal.com/gui/file/e197c583f57e6c560b576278233e3a… · virustotal.com/gui/file/77680fb906476f0d84e15d5032f091… · virustotal.com/gui/file/e81255ff6e0ed937603748c1442ce9…

    domainconfig.zapto.org
    domainmacfee-update.serveftp.com
    domainmicrosoftonline.com.authorizeddns.net
    domainorg.misecure.com
    urlhttp://107.191.61.40
    urlhttp://139.162.87.180
    url_path/index.htmld?flag=
    url_path/index.htmld?flagpro=

  9. 2 domain5 yrs ago

    twitter.com/nahamike01/status/1467499135171710977 · virustotal.com/gui/ip-address/103.195.150.181/relations · virustotal.com/gui/file/c2b23689ca1c57f7b7b0c2fd95bfef… · virustotal.com/gui/file/8c3df0e4d7ff0578d143785342a803…

    centos.onthewifi.com
    redhatstate.hopto.org

  10. 1 url5 yrs ago

    twitter.com/nao_sec/status/1446277006690119681 · insight-jp.nttsecurity.com/post/102h7vx/blacktechflagpro (Japanese) · virustotal.com/gui/ip-address/45.32.23.140/relations · virustotal.com/gui/ip-address/45.76.184.227/relations · virustotal.com/gui/file/54e6ea47eb04634d3e87fd7787e213… · virustotal.com/gui/file/ba27ae12e6f3c2c87fd2478072dfa2… · virustotal.com/gui/file/655ca39beb2413803af099879401e6… · virustotal.com/gui/file/e197c583f57e6c560b576278233e3a… · virustotal.com/gui/file/77680fb906476f0d84e15d5032f091… · virustotal.com/gui/file/e81255ff6e0ed937603748c1442ce9…

    http://172.104.109.217

  11. 1 domain5 yrs ago

    twitter.com/BushidoToken/status/1446602218170376199 · virustotal.com/gui/ip-address/45.32.61.175/relations · virustotal.com/gui/file/358bc9f08b34d9323bbca6eeb23f19…

    systeminfo.centosupdates.com

  12. 4 domain5 yrs ago

    twitter.com/BushidoToken/status/1446602218170376199 · virustotal.com/gui/ip-address/45.32.61.175/relations · virustotal.com/gui/file/358bc9f08b34d9323bbca6eeb23f19…

    centosupdate.dynamic-dns.net
    centosupdates.com
    centrosupdate.proxydns.com
    update.centosupdates.com

  13. 2 domain5 yrs ago

    unit42.paloaltonetworks.com/bendybear-shellcode-blacktech

    inkeslive.com
    rutentw.com

  14. 2 domain5 yrs ago

    blog.jpcert.or.jp/2018/06/plead-downloader-used-by-blackt…

    totalpople.info
    yasonbin.info

  15. 2 domain5 yrs ago

    unit42.paloaltonetworks.com/bendybear-shellcode-blacktech

    web2008.rutentw.com
    wg1.inkeslive.com

  16. 1 domain6 yrs ago

    twitter.com/8th_grey_owl/status/1262047338006065155

    harb.bbsindex.com

  17. 1 domain7 yrs ago

    otx.alienvault.com/pulse/5db0438c08e53c4d7931e3f4

    update.panasocin.com

  18. 1 domain7 yrs ago

    blog.jpcert.or.jp/2018/06/plead-downloader-used-by-blackt…

    panasocin.com

  19. 1 domain8 yrs ago

    welivesecurity.com/2018/07/09/certificates-stolen-taiwanes…

    amazon.panasocin.com

  20. 3 domain8 yrs ago

    blog.jpcert.or.jp/2018/06/plead-downloader-used-by-blackt…

    em.totalpople.info
    gstrap.jkub.com
    woc.yasonbin.info

  21. 1 domain8 yrs ago

    blog.jpcert.or.jp/2018/06/plead-downloader-used-by-blackt… · welivesecurity.com/2018/07/09/certificates-stolen-taiwanes…

    office.panasocin.com

  22. 1 domain8 yrs ago

    welivesecurity.com/2018/07/09/certificates-stolen-taiwanes…

    okinawas.ssl443.org

Further reading 44

4 more, and the report behind every indicator, in G0098.json.