Blackwood is a China-aligned advanced persistent threat cluster associated with cyber-espionage activity and the deployment of the modular Windows implant NSPX30. The group is notable for adversary-in-the-middle operations that hijack legitimate software update mechanisms to gain initial access, including abuse of update traffic for widely used Chinese applications such as Tencent QQ, Sogou Pinyin, and WPS Office. Observed delivery chains involve interception of unencrypted update requests and substitution of malicious payloads delivered through otherwise legitimate software workflows. NSPX30 is a modular toolset comprising loaders, an orchestrator, a backdoor, and multiple plugin groups. Blackwood has used persistence via a Winsock Namespace Provider DLL so that malicious components are loaded into processes using Winsock. The implant supports downloading and loading additional components, gathering system information, communicating with command-and-control infrastructure, extracting or loading plugins, and exfiltrating collected data. Reported plugin functionality includes theft of application data, SQL interaction, in-memory function hooking, and audio-related collection capabilities. Blackwood has also employed allowlisting-bypass and other defense-evasion measures involving Chinese security products. Research has linked NSPX30 to older malware lineages and tooling, including DCM, also known as Dark Specter, and Project Wood, suggesting a long-running development ecosystem. Blackwood is part of a broader set of China-aligned intrusion actors known to use update hijacking and AitM techniques for access operations. Victimology includes individuals and organizations in China, Japan, and the United Kingdom, including manufacturing-related entities. The activity profile is consistent with state-aligned espionage objectives rather than financially motivated crime.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
10 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Used abuse of Sogou Pinyin’s update mechanism to deploy the NSPX30 implant (as reported by ESET).
Chinese intrusion cluster abusing Sogou Pinyin’s software update mechanism to deploy the NSPX30 implant.
Referenced as conducting attacks against telecom operators using the NSPX30 implant.
China-aligned activity reported using DNS hijacking/man-in-the-middle techniques to manipulate update traffic for initial access.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.