LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G0098: BlackTech

BlackTech is a suspected Chinese cyber espionage group that has primarily targeted organizations in East Asia--particularly Taiwan, Japan, and Hong Kong--and the US since at least 2013. BlackTech has used a combination of custom malware, dual-use tools, and living off the land tactics to compromise media, construction, engineering, electronics, and financial company networks.[1][2][3]

EnterpriseG0098GroupObject v2.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

BlackTech matters because ATT&CK describes it as a long-running suspected cyber espionage group using a mix of custom malware, dual-use tools, and living-off-the-land behavior against organizations in East Asia, particularly Taiwan, Japan, and Hong Kong, and the US. For executives, the decision value is not the name alone: it is whether the organization can withstand targeted initial access through phishing or public-facing applications, recognize legitimate admin-tool abuse such as PsExec, and investigate custom Windows malware/RAT activity without relying only on commodity indicators.

Executive priority

Prioritize BlackTech as a threat-informed validation scenario if the business operates in or depends on East Asia, the US, or sectors named in the ATT&CK description: media, construction, engineering, electronics, finance, and, from related software context, defense, communications, and Japanese targets. Leaders should ask whether email security, public-facing application exposure management, endpoint visibility, certificate trust controls, and lateral movement monitoring produce audit-ready evidence. The business risk is espionage-oriented compromise that may remain operationally quiet while affecting confidentiality, partner trust, incident response cost, and resilience of critical business networks.

Technical view

ATT&CK provides no official detection text for the group, so SOC and IR teams should build coverage from the relationship context. Validate controls and telemetry around initial access via Spearphishing Attachment, Spearphishing Link, and Exploit Public-Facing Application; execution through Malicious File, Malicious Link, Exploitation for Client Execution, Native API, and DLL abuse; discovery via Network Service Discovery; lateral movement via SSH and PsExec; and resource-development indicators involving tools, code-signing certificates, and digital certificates. Related Windows malware/software includes PLEAD, TSCookie, Kivars, Waterbear, Flagpro, and PsExec. Treat PsExec and SSH carefully because they are legitimate administrative mechanisms as well as adversary tradecraft.

Likely telemetry

  • Email gateway and collaboration-suite logs for targeted attachments, links, sender patterns, and user click/open events
  • Endpoint process, module/DLL load, file creation, script, and command-line telemetry on Windows, Linux, and macOS where related techniques apply
  • Windows service creation, remote execution, and administrative share activity relevant to PsExec-like behavior
  • SSH authentication, session, source/destination, and command/audit logs for Linux, macOS, and ESXi environments where SSH is enabled
  • Network flow, DNS, proxy, TLS certificate, and egress telemetry to support investigation of RAT/downloaders and hidden or unusual network behavior

Detection direction

  • Map detections to the specific ATT&CK relationships rather than to the group name alone; the supplied object has no official detection guidance.
  • Tune for combinations: phishing delivery followed by user execution, unusual child processes, DLL abuse, downloader/RAT behavior, network discovery, and remote movement.
  • Baseline legitimate PsExec and SSH administration so alerts can focus on unusual source hosts, destinations, timing, accounts, or service creation patterns.
  • Review blind spots around signed binaries and trusted certificates, because the relationship context includes code-signing certificates and digital certificates as adversary resources.
  • For public-facing applications, correlate exploit attempts with subsequent process creation, outbound connections, credential use, or lateral movement.

Mitigation priorities

  • Start with exposure reduction: inventory and patch Internet-facing applications, restrict unnecessary exposed services, and validate logging on externally reachable systems.
  • Harden email and user-execution paths with attachment/link inspection, safe handling of risky file types, and user reporting workflows, while measuring whether events reach the SOC.
  • Constrain lateral movement by limiting administrative tool use, controlling PsExec-like remote execution, hardening SSH access, enforcing least privilege, and segmenting critical systems.
  • Strengthen endpoint controls for DLL abuse, suspicious downloader/RAT execution, and unusual process/module activity, especially on Windows systems referenced by related software.
  • Implement certificate governance: monitor trusted code-signing usage and certificate anomalies, and avoid assuming signed or TLS-protected activity is benign.
Additional notes and limits

This take is derived from the supplied ATT&CK group object, external references, and stated relationships. The strongest defensive value is using BlackTech as a threat-informed scenario for espionage-style intrusions that blend custom malware with legitimate tools and living-off-the-land behavior. Local relevance depends on geography, sector, exposed services, identity architecture, and telemetry maturity.

The ATT&CK group object lists no platforms or tactics directly and provides no official detection section. Platform and tactic guidance here is inferred only from supplied related techniques and software. The references support historical reporting and aliases, but this output does not claim current activity, customer exposure, or guaranteed detection coverage.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

BlackTech

BlackTech is a suspected Chinese cyber espionage group that has primarily targeted organizations in East Asia--particularly Taiwan, Japan, and Hong Kong--and the US since at least 2013. BlackTech has used a combination of custom malware, dual-use tools, and living off the land tactics to compromise media, construction, engineering, electronics, and financial company networks.[1][2][3]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

14 rows
DomainIDNameRelationship / procedure
EnterpriseT1566.002Spearphishing LinkSub-technique

BlackTech has used spearphishing e-mails with links to cloud services to deliver malware.[1]

EnterpriseT1204.001Malicious LinkSub-technique

BlackTech has used e-mails with malicious links to lure victims into installing malware.[1]

EnterpriseT1588.003Code Signing CertificatesSub-technique

BlackTech has used stolen code-signing certificates for its malicious payloads.[2]

EnterpriseT1046Network Service Discovery

BlackTech has used the SNScan tool to find other potential targets on victim networks.[2]

EnterpriseT1588.002ToolSub-technique

BlackTech has obtained and used tools such as Putty, SNScan, and PsExec for its operations.[2]

EnterpriseT1190Exploit Public-Facing Application

BlackTech has exploited a buffer overflow vulnerability in Microsoft Internet Information Services (IIS) 6.0, CVE-2017-7269, in order to establish a new HTTP or command and control (C2) server.[1]

EnterpriseT1021.004SSHSub-technique

BlackTech has used Putty for remote access.[2]

EnterpriseT1106Native API

BlackTech has used built-in API functions.[6]

EnterpriseT1203Exploitation for Client Execution

BlackTech has exploited multiple vulnerabilities for execution, including Microsoft Office vulnerabilities CVE-2012-0158, CVE-2014-6352, CVE-2017-0199, and Adobe Flash CVE-2015-5119.[1]

EnterpriseT1566.001Spearphishing AttachmentSub-technique

BlackTech has used spearphishing e-mails with malicious password-protected archived files (ZIP or RAR) to deliver malware.[1][7]

EnterpriseT1036.002Right-to-Left OverrideSub-technique

BlackTech has used right-to-left-override to obfuscate the filenames of malicious e-mail attachments.[1]

EnterpriseT1574.001DLLSub-technique

BlackTech has used DLL side loading by giving DLLs hardcoded names and placing them in searched directories.[5]

EnterpriseT1204.002Malicious FileSub-technique

BlackTech has used e-mails with malicious documents to lure victims into installing malware.[1][7]

EnterpriseT1588.004Digital CertificatesSub-technique

BlackTech has used valid, stolen digital certificates for some of their malware and tools.[9]

Associated objects

Groups, software, and campaigns

MalwareEnterprise

S0435: PLEAD

PLEAD is a remote access tool (RAT) and downloader used by BlackTech in targeted attacks in East Asia including Taiwan, Japan, and Hong Kong.[1][2] PLEAD has also been referred to as TSCookie, though more recent reporting indicates likely separation between the two. PLEAD was observed in use as early as March 2017.[3][2]

Windows
ToolEnterprise

S0029: PsExec

PsExec is a free Microsoft tool that can be used to execute a program on another computer. It is used by IT administrators and attackers.[1][2]

Windows
MalwareEnterprise

S0696: Flagpro

Flagpro is a Windows-based, first-stage downloader that has been used by BlackTech since at least October 2020. It has primarily been used against defense, media, and communications companies in Japan.[1]

Windows
MalwareEnterprise

S0579: Waterbear

Waterbear is modular malware attributed to BlackTech that has been used primarily for lateral movement, decrypting, and triggering payloads and is capable of hiding network behaviors.[1]

Windows
Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
2.0
Created
Modified
Raw hash
18585c51b455ff4d...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.12.0Current bundle18585c51b455…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    TrendMicro BlackTech June 2017

    Bermejo, L., et al. (2017, June 22). Following the Trail of BlackTech’s Cyber Espionage Campaigns. Retrieved May 5, 2020.

    Open source URL
  2. [2]
    Symantec Palmerworm Sep 2020

    Threat Intelligence. (2020, September 29). Palmerworm: Espionage Gang Targets the Media, Finance, and Other Sectors. Retrieved March 25, 2022.

    Open source URL
  3. [3]
    Reuters Taiwan BlackTech August 2020

    Lee, Y. (2020, August 19). Taiwan says China behind cyberattacks on government agencies, emails. Retrieved April 6, 2022.

    Open source URL
  4. [4]
    JPCert PLEAD Downloader June 2018

    Tomonaga, S. (2018, June 8). PLEAD Downloader Used by BlackTech. Retrieved May 6, 2020.

    Open source URL
  5. [5]
    Trend Micro Waterbear December 2019

    Su, V. et al. (2019, December 11). Waterbear Returns, Uses API Hooking to Evade Security. Retrieved February 22, 2021.

    Open source URL
  6. [6]
    IronNet BlackTech Oct 2021

    Demboski, M., et al. (2021, October 26). China cyber attacks: the current threat landscape. Retrieved March 25, 2022.

    Open source URL
  7. [7]
    NTT Security Flagpro new December 2021

    Hada, H. (2021, December 28). Flagpro The new malware used by BlackTech. Retrieved March 25, 2022.

    Open source URL
  8. [8]
    JPCert TSCookie March 2018

    Tomonaga, S. (2018, March 6). Malware “TSCookie”. Retrieved May 6, 2020.

    Open source URL
  9. [9]
    ESET PLEAD Malware July 2018

    Cherepanov, A.. (2018, July 9). Certificates stolen from Taiwanese tech‑companies misused in Plead malware campaign. Retrieved May 6, 2020.

    Open source URL
  10. [10]
    IronNet BlackTech Oct 2021

    Demboski, M., et al. (2021, October 26). China cyber attacks: the current threat landscape. Retrieved March 25, 2022.

    Open source URL
  11. [11]
    IronNet BlackTech Oct 2021

    Demboski, M., et al. (2021, October 26). China cyber attacks: the current threat landscape. Retrieved March 25, 2022.

    Open source URL
  12. [12]
    Palmerworm

    (Citation: Symantec Palmerworm Sep 2020)(Citation: IronNet BlackTech Oct 2021)

  13. [13]
    Palmerworm

    (Citation: Symantec Palmerworm Sep 2020)(Citation: IronNet BlackTech Oct 2021)

  14. [14]
    Palmerworm

    (Citation: Symantec Palmerworm Sep 2020)(Citation: IronNet BlackTech Oct 2021)

  15. [15]
    Reuters Taiwan BlackTech August 2020

    Lee, Y. (2020, August 19). Taiwan says China behind cyberattacks on government agencies, emails. Retrieved April 6, 2022.

    Open source URL
  16. [16]
    Reuters Taiwan BlackTech August 2020

    Lee, Y. (2020, August 19). Taiwan says China behind cyberattacks on government agencies, emails. Retrieved April 6, 2022.

    Open source URL
  17. [17]
    Symantec Palmerworm Sep 2020

    Threat Intelligence. (2020, September 29). Palmerworm: Espionage Gang Targets the Media, Finance, and Other Sectors. Retrieved March 25, 2022.

    Open source URL
  18. [18]
    Symantec Palmerworm Sep 2020

    Threat Intelligence. (2020, September 29). Palmerworm: Espionage Gang Targets the Media, Finance, and Other Sectors. Retrieved March 25, 2022.

    Open source URL
  19. [19]
    TrendMicro BlackTech June 2017

    Bermejo, L., et al. (2017, June 22). Following the Trail of BlackTech’s Cyber Espionage Campaigns. Retrieved May 5, 2020.

    Open source URL
  20. [20]
    TrendMicro BlackTech June 2017

    Bermejo, L., et al. (2017, June 22). Following the Trail of BlackTech’s Cyber Espionage Campaigns. Retrieved May 5, 2020.

    Open source URL
  21. [21]
    mitre-attackG0098
    Open source URL
  22. [22]
    mitre-attackG0098
    Open source URL
  23. [23]
    mitre-attackG0098
    Open source URL
  24. [24]
    TrendMicro BlackTech June 2017

    Bermejo, L., et al. (2017, June 22). Following the Trail of BlackTech’s Cyber Espionage Campaigns. Retrieved May 5, 2020.

    Open source URL
  25. [25]
    TrendMicro BlackTech June 2017

    Bermejo, L., et al. (2017, June 22). Following the Trail of BlackTech’s Cyber Espionage Campaigns. Retrieved May 5, 2020.

    Open source URL
  26. [26]
    TrendMicro BlackTech June 2017

    Bermejo, L., et al. (2017, June 22). Following the Trail of BlackTech’s Cyber Espionage Campaigns. Retrieved May 5, 2020.

    Open source URL
  27. [27]
    TrendMicro BlackTech June 2017

    Bermejo, L., et al. (2017, June 22). Following the Trail of BlackTech’s Cyber Espionage Campaigns. Retrieved May 5, 2020.

    Open source URL
  28. [28]
    JPCert PLEAD Downloader June 2018

    Tomonaga, S. (2018, June 8). PLEAD Downloader Used by BlackTech. Retrieved May 6, 2020.

    Open source URL
  29. [29]
    Symantec Palmerworm Sep 2020

    Threat Intelligence. (2020, September 29). Palmerworm: Espionage Gang Targets the Media, Finance, and Other Sectors. Retrieved March 25, 2022.

    Open source URL
  30. [30]
    Symantec Palmerworm Sep 2020

    Threat Intelligence. (2020, September 29). Palmerworm: Espionage Gang Targets the Media, Finance, and Other Sectors. Retrieved March 25, 2022.

    Open source URL
  31. [31]
    Trend Micro Waterbear December 2019

    Su, V. et al. (2019, December 11). Waterbear Returns, Uses API Hooking to Evade Security. Retrieved February 22, 2021.

    Open source URL
  32. [32]
    TrendMicro BlackTech June 2017

    Bermejo, L., et al. (2017, June 22). Following the Trail of BlackTech’s Cyber Espionage Campaigns. Retrieved May 5, 2020.

    Open source URL
  33. [33]
    TrendMicro BlackTech June 2017

    Bermejo, L., et al. (2017, June 22). Following the Trail of BlackTech’s Cyber Espionage Campaigns. Retrieved May 5, 2020.

    Open source URL
  34. [34]
    Symantec Palmerworm Sep 2020

    Threat Intelligence. (2020, September 29). Palmerworm: Espionage Gang Targets the Media, Finance, and Other Sectors. Retrieved March 25, 2022.

    Open source URL
  35. [35]
    Symantec Palmerworm Sep 2020

    Threat Intelligence. (2020, September 29). Palmerworm: Espionage Gang Targets the Media, Finance, and Other Sectors. Retrieved March 25, 2022.

    Open source URL
  36. [36]
    Symantec Palmerworm Sep 2020

    Threat Intelligence. (2020, September 29). Palmerworm: Espionage Gang Targets the Media, Finance, and Other Sectors. Retrieved March 25, 2022.

    Open source URL
  37. [37]
    Symantec Palmerworm Sep 2020

    Threat Intelligence. (2020, September 29). Palmerworm: Espionage Gang Targets the Media, Finance, and Other Sectors. Retrieved March 25, 2022.

    Open source URL
  38. [38]
    Symantec Palmerworm Sep 2020

    Threat Intelligence. (2020, September 29). Palmerworm: Espionage Gang Targets the Media, Finance, and Other Sectors. Retrieved March 25, 2022.

    Open source URL
  39. [39]
    Symantec Palmerworm Sep 2020

    Threat Intelligence. (2020, September 29). Palmerworm: Espionage Gang Targets the Media, Finance, and Other Sectors. Retrieved March 25, 2022.

    Open source URL
  40. [40]
    Symantec Palmerworm Sep 2020

    Threat Intelligence. (2020, September 29). Palmerworm: Espionage Gang Targets the Media, Finance, and Other Sectors. Retrieved March 25, 2022.

    Open source URL
  41. [41]
    Symantec Palmerworm Sep 2020

    Threat Intelligence. (2020, September 29). Palmerworm: Espionage Gang Targets the Media, Finance, and Other Sectors. Retrieved March 25, 2022.

    Open source URL
  42. [42]
    TrendMicro BlackTech June 2017

    Bermejo, L., et al. (2017, June 22). Following the Trail of BlackTech’s Cyber Espionage Campaigns. Retrieved May 5, 2020.

    Open source URL
  43. [43]
    TrendMicro BlackTech June 2017

    Bermejo, L., et al. (2017, June 22). Following the Trail of BlackTech’s Cyber Espionage Campaigns. Retrieved May 5, 2020.

    Open source URL
  44. [44]
    Symantec Palmerworm Sep 2020

    Threat Intelligence. (2020, September 29). Palmerworm: Espionage Gang Targets the Media, Finance, and Other Sectors. Retrieved March 25, 2022.

    Open source URL
  45. [45]
    Symantec Palmerworm Sep 2020

    Threat Intelligence. (2020, September 29). Palmerworm: Espionage Gang Targets the Media, Finance, and Other Sectors. Retrieved March 25, 2022.

    Open source URL
  46. [46]
    TrendMicro BlackTech June 2017

    Bermejo, L., et al. (2017, June 22). Following the Trail of BlackTech’s Cyber Espionage Campaigns. Retrieved May 5, 2020.

    Open source URL
  47. [47]
    TrendMicro BlackTech June 2017

    Bermejo, L., et al. (2017, June 22). Following the Trail of BlackTech’s Cyber Espionage Campaigns. Retrieved May 5, 2020.

    Open source URL
  48. [48]
    Symantec Palmerworm Sep 2020

    Threat Intelligence. (2020, September 29). Palmerworm: Espionage Gang Targets the Media, Finance, and Other Sectors. Retrieved March 25, 2022.

    Open source URL
  49. [49]
    Symantec Palmerworm Sep 2020

    Threat Intelligence. (2020, September 29). Palmerworm: Espionage Gang Targets the Media, Finance, and Other Sectors. Retrieved March 25, 2022.

    Open source URL
  50. [50]
    IronNet BlackTech Oct 2021

    Demboski, M., et al. (2021, October 26). China cyber attacks: the current threat landscape. Retrieved March 25, 2022.

    Open source URL
  51. [51]
    IronNet BlackTech Oct 2021

    Demboski, M., et al. (2021, October 26). China cyber attacks: the current threat landscape. Retrieved March 25, 2022.

    Open source URL
  52. [52]
    TrendMicro BlackTech June 2017

    Bermejo, L., et al. (2017, June 22). Following the Trail of BlackTech’s Cyber Espionage Campaigns. Retrieved May 5, 2020.

    Open source URL
  53. [53]
    TrendMicro BlackTech June 2017

    Bermejo, L., et al. (2017, June 22). Following the Trail of BlackTech’s Cyber Espionage Campaigns. Retrieved May 5, 2020.

    Open source URL
  54. [54]
    NTT Security Flagpro new December 2021

    Hada, H. (2021, December 28). Flagpro The new malware used by BlackTech. Retrieved March 25, 2022.

    Open source URL
  55. [55]
    TrendMicro BlackTech June 2017

    Bermejo, L., et al. (2017, June 22). Following the Trail of BlackTech’s Cyber Espionage Campaigns. Retrieved May 5, 2020.

    Open source URL
  56. [56]
    TrendMicro BlackTech June 2017

    Bermejo, L., et al. (2017, June 22). Following the Trail of BlackTech’s Cyber Espionage Campaigns. Retrieved May 5, 2020.

    Open source URL
  57. [57]
    TrendMicro BlackTech June 2017

    Bermejo, L., et al. (2017, June 22). Following the Trail of BlackTech’s Cyber Espionage Campaigns. Retrieved May 5, 2020.

    Open source URL
  58. [58]
    TrendMicro BlackTech June 2017

    Bermejo, L., et al. (2017, June 22). Following the Trail of BlackTech’s Cyber Espionage Campaigns. Retrieved May 5, 2020.

    Open source URL
  59. [59]
    Trend Micro Waterbear December 2019

    Su, V. et al. (2019, December 11). Waterbear Returns, Uses API Hooking to Evade Security. Retrieved February 22, 2021.

    Open source URL
  60. [60]
    Trend Micro Waterbear December 2019

    Su, V. et al. (2019, December 11). Waterbear Returns, Uses API Hooking to Evade Security. Retrieved February 22, 2021.

    Open source URL
  61. [61]
    JPCert TSCookie March 2018

    Tomonaga, S. (2018, March 6). Malware “TSCookie”. Retrieved May 6, 2020.

    Open source URL
  62. [62]
    NTT Security Flagpro new December 2021

    Hada, H. (2021, December 28). Flagpro The new malware used by BlackTech. Retrieved March 25, 2022.

    Open source URL
  63. [63]
    NTT Security Flagpro new December 2021

    Hada, H. (2021, December 28). Flagpro The new malware used by BlackTech. Retrieved March 25, 2022.

    Open source URL
  64. [64]
    Trend Micro Waterbear December 2019

    Su, V. et al. (2019, December 11). Waterbear Returns, Uses API Hooking to Evade Security. Retrieved February 22, 2021.

    Open source URL
  65. [65]
    Trend Micro Waterbear December 2019

    Su, V. et al. (2019, December 11). Waterbear Returns, Uses API Hooking to Evade Security. Retrieved February 22, 2021.

    Open source URL
  66. [66]
    NTT Security Flagpro new December 2021

    Hada, H. (2021, December 28). Flagpro The new malware used by BlackTech. Retrieved March 25, 2022.

    Open source URL
  67. [67]
    TrendMicro BlackTech June 2017

    Bermejo, L., et al. (2017, June 22). Following the Trail of BlackTech’s Cyber Espionage Campaigns. Retrieved May 5, 2020.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.