Threat group.View on attack.mitre.org
BlackTech is a suspected Chinese cyber espionage group that has primarily targeted organizations in East Asia--particularly Taiwan, Japan, and Hong Kong--and the US since at least 2013. BlackTech has used a combination of custom malware, dual-use tools, and living off the land tactics to compromise media, construction, engineering, electronics, and financial company networks.
| Technique | Procedure example |
|---|---|
| T1021.004 SSH |
BlackTech has used Putty for remote access. |
| T1036.002 Right-to-Left Override |
BlackTech has used right-to-left-override to obfuscate the filenames of malicious e-mail attachments. |
| T1046 Network Service Discovery |
BlackTech has used the SNScan tool to find other potential targets on victim networks. |
| T1106 Native API |
BlackTech has used built-in API functions. |
| T1190 Exploit Public-Facing Application |
BlackTech has exploited a buffer overflow vulnerability in Microsoft Internet Information Services (IIS) 6.0, CVE-2017-7269, in order to establish a new HTTP or command and control (C2) server. |
| T1203 Exploitation for Client Execution |
BlackTech has exploited multiple vulnerabilities for execution, including Microsoft Office vulnerabilities CVE-2012-0158, CVE-2014-6352, CVE-2017-0199, and Adobe Flash CVE-2015-5119. |
| T1204.001 Malicious Link |
BlackTech has used e-mails with malicious links to lure victims into installing malware. |
| T1204.002 Malicious File |
BlackTech has used e-mails with malicious documents to lure victims into installing malware. |
| T1566.001 Spearphishing Attachment |
BlackTech has used spearphishing e-mails with malicious password-protected archived files (ZIP or RAR) to deliver malware. |
| T1566.002 Spearphishing Link |
BlackTech has used spearphishing e-mails with links to cloud services to deliver malware. |
| T1574.001 DLL |
BlackTech has used DLL side loading by giving DLLs hardcoded names and placing them in searched directories. |
| T1588.002 Tool |
BlackTech has obtained and used tools such as Putty, SNScan, and PsExec for its operations. |
| T1588.003 Code Signing Certificates |
BlackTech has used stolen code-signing certificates for its malicious payloads. |
| T1588.004 Digital Certificates |
BlackTech has used valid, stolen digital certificates for some of their malware and tools. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.