BlackTech
Aliases: Palmerworm
BlackTech is a suspected Chinese cyber espionage group that has primarily targeted organizations in East Asia--particularly Taiwan, Japan, and Hong Kong--and the US since at least 2013. BlackTech has used a combination of custom malware, dual-use tools, and living off the land tactics to compromise media, construction, engineering, electronics, and financial company networks.
Open interactive actor investigation
ATT&CK techniques
T1566.002
Spearphishing LinkT1204.001
Malicious LinkT1588.003
Code Signing CertificatesT1046
Network Service DiscoveryT1588.002
ToolT1190
Exploit Public-Facing ApplicationT1021.004
SSHT1106
Native APIT1203
Exploitation for Client ExecutionT1566.001
Spearphishing AttachmentT1036.002
Right-to-Left OverrideT1574.002
DLL Side-LoadingT1204.002
Malicious FileT1588.004
Digital Certificates
Spearphishing LinkT1204.001
Malicious LinkT1588.003
Code Signing CertificatesT1046
Network Service DiscoveryT1588.002
ToolT1190
Exploit Public-Facing ApplicationT1021.004
SSHT1106
Native APIT1203
Exploitation for Client ExecutionT1566.001
Spearphishing AttachmentT1036.002
Right-to-Left OverrideT1574.002
DLL Side-LoadingT1204.002
Malicious FileT1588.004
Digital Certificates