BlackTech is a long-running China-linked cyber espionage threat actor active since at least 2010 and widely tracked under aliases including APT24, Circuit Panda, Palmerworm, Canary Typhoon, and Pitty Panda. The group is associated with Chinese state interests and is assessed to support intelligence collection objectives. BlackTech has primarily targeted organizations in East Asia and the United States, with especially persistent activity against Japan and Taiwan. BlackTech is known for intrusions against government and private-sector organizations, including technology, telecommunications, media, electronics, industrial enterprises, and critical infrastructure. Reporting also links the group to targeting of Taiwan’s energy, healthcare, communications, government, and technology sectors as part of broader strategic Chinese cyber activity. The actor uses multiple initial access and intrusion methods, including spearphishing with malicious documents and password-protected archives, exploitation of public-facing applications, and compromise of network infrastructure. BlackTech has been publicly associated with abuse of routers and other edge devices, including modification of router firmware, disabling of logging, and use of trusted network relationships between subsidiaries, branch offices, and headquarters to pivot deeper into victim environments while maintaining stealth and persistence. Post-compromise tradecraft includes lateral movement over SSH, use of legitimate administrative tools such as PuTTY, PsExec, and network scanners, and deployment of custom malware families including Flagpro, BlueShell, BendyBear, BTSDoor, FakeDead, FrontShell, IconDown, PLEAD, SpiderPig, SpiderSpring, SpiderStack, TSCookie, WaterBear, and Bifrose. Recent reporting tied BlackTech to a Linux variant of BlueShell used in Japan-focused operations. That malware supported remote command execution, file transfer, interactive shell access, host reconnaissance, and SOCKS5 proxying, while employing anti-forensic measures such as process masquerading and removal of deployed artifacts from disk. Newer variants also tunneled command-and-control traffic through victim proxy infrastructure to blend with legitimate network activity. BlackTech consistently demonstrates strong defense-evasion tradecraft, including custom malware, artifact cleanup, process disguise, disabling of device logging, blending with normal network operations, and use of stolen code-signing certificates. The group’s operations are best characterized as strategic cyber espionage focused on persistent access, internal pivoting, and theft of sensitive information and intellectual property rather than disruptive or financially motivated activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
58 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
21 malware families attributed to this actor across reporting.
16 additional families tracked in Mallory.
15 CVEs this actor has used in observed campaigns. 15 of them exploited in the wild.
...has exploited client software vulnerabilities for execution, such as Microsoft Word CVE-2012-0158...
BlackTech has exploited multiple vulnerabilities for execution, including Microsoft Office vulnerabilities... CVE-2014-6352...
...and Adobe Flash CVE-2015-5119.
...used exploits for... Word (CVE-2017-0199)...
BlackTech has exploited a buffer overflow vulnerability in Microsoft Internet Information Services (IIS) 6.0, CVE-2017-7269, in order to establish a new HTTP or command and control (C2) server.
10 more CVEs tied to this actor tracked in Mallory.
64 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting cyberespionage-focused post-compromise operations against organizations in Japan using a Linux variant of BlueShell for remote command execution, file transfer, shell access, SOCKS5 proxying, and stealthy persistence/evasion after SSH-based lateral movement.
Listed as an associated threat actor in the detection annotation for exploitation of the public-facing PTC Windchill vulnerability CVE-2026-4681.
Named threat actor referenced in retrospective threat reporting.
Listed in the detection annotations as a threat actor associated with EFI volume mounting / installation-related behavior.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.