AdversaryGraph public intelligence page
This page is part of Threat Matrix, the public browser workspace for the main AdversaryGraph platform. Use it for ATT&CK pivots, actor and technique context, similarity leads, detection coverage review, and analyst-ready investigation paths.
Validation disclaimer: TTP overlap, actor similarity, generated summaries, and coverage findings are investigation leads, not attribution proof or operational validation without analyst review.
Main AdversaryGraph project Documentation Malware Analysis GitHub
BlackTech
Aliases: Palmerworm
BlackTech is a suspected Chinese cyber espionage group that has primarily targeted organizations in East Asia--particularly Taiwan, Japan, and Hong Kong--and the US since at least 2013. BlackTech has used a combination of custom malware, dual-use tools, and living off the land tactics to compromise media, construction, engineering, electronics, and financial company networks.
Open interactive actor investigation
ATT&CK techniques
Spearphishing LinkT1204.001
Malicious LinkT1588.003
Code Signing CertificatesT1046
Network Service DiscoveryT1588.002
ToolT1190
Exploit Public-Facing ApplicationT1021.004
SSHT1106
Native APIT1203
Exploitation for Client ExecutionT1566.001
Spearphishing AttachmentT1036.002
Right-to-Left OverrideT1574.002
DLL Side-LoadingT1204.002
Malicious FileT1588.004
Digital Certificates
Correlated CTI and IR reports
Continue the investigation
Cyber Knowledge routes
These contextual routes explain behaviors associated with this ATT&CK group record. They support learning and investigation planning; they do not add attribution evidence.
Vulnerability Research & Exploit Development · explicit-idWeakness taxonomy and vulnerability identity
Vulnerability Research & Exploit Development · topic-matchData classification, storage, cryptography, keys, backup, and deletion
Cloud Security · topic-matchCloud logging, detection engineering, ATT CK, and response automation
Cloud Security · topic-matchResearch governance, authorization, and safety
Vulnerability Research & Exploit Development · topic-matchContainer image, registry, runtime, and host security
Cloud Security · topic-matchModule 1 — Mission, authorization, and methodology
Red Team & Offensive Security · topic-matchModule 9 — AI-assisted offensive security and MCP
Red Team & Offensive Security · topic-matchModule 2 — The Intelligence Cycle Intelligence Types
Cyber Threat Intelligence (CTI) · topic-matchCoordinated disclosure, PSIRT, scoring, remediation, and regression
Vulnerability Research & Exploit Development · topic-matchRequirements, ownership, inventory, and data flow
Secure Code & Application Security · topic-matchSource review and static analysis
Vulnerability Research & Exploit Development · topic-match