BlackTech is a China-linked threat actor, also described as tied to the government of China, with activity reported since at least 2010 and in some reporting since at least 2011 under the alias APT24. Known aliases in the provided content include APT24, Canary Typhoon, Circuit Panda, Palmerworm, and Pity/Pitty Panda. The group has targeted organizations in the United States, Japan, Taiwan, and East Asia, including government entities and private-sector victims in industrial, technology, media, electronics, telecommunications, healthcare, communications, administration, and energy-related sectors. Taiwan’s NSB also named BlackTech among Chinese groups involved in sustained targeting of Taiwan’s critical infrastructure. The provided content describes BlackTech as an espionage-focused actor that seeks persistent access and steals intellectual property and sensitive data. Reported tradecraft includes spearphishing emails with malicious documents, including password-protected ZIP or RAR archives, to induce user execution; exploitation of public-facing applications; deployment of web shells and IIS components for persistence; use of SSH for lateral movement; and abuse of trusted network relationships to pivot from subsidiaries or branch offices into headquarters and broader enterprise networks. BlackTech has specifically targeted branch routers and other edge devices, modified router firmware for persistence, disabled router logging, and in some cases abused Cisco automation tooling to remove traces of activity. The group has used custom malware and a broad malware/toolset including Flagpro, BendyBear, Bifrose, BTSDoor, FakeDead, TSCookie, FrontShell, IconDown, PLEAD, SpiderPig, SpiderSpring, SpiderStack, WaterBear, and badAudio. The content also states BlackTech has obtained and used tools such as PuTTY, SNScan, and PsExec, and has used stolen code-signing certificates to make malicious software appear legitimate. The content further associates BlackTech/APT24 with badAudio, a first-stage downloader that performs host reconnaissance, obfuscates strings, encrypts collected data with AES-256 in CTR mode, and sends it in HTTP Cookie headers to command-and-control infrastructure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
55 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 malware families attributed to this actor across reporting.
15 additional families tracked in Mallory.
15 CVEs this actor has used in observed campaigns. 15 of them exploited in the wild.
...has exploited client software vulnerabilities for execution, such as Microsoft Word CVE-2012-0158...
BlackTech has exploited multiple vulnerabilities for execution, including Microsoft Office vulnerabilities... CVE-2014-6352...
...and Adobe Flash CVE-2015-5119.
...used exploits for... Word (CVE-2017-0199)...
BlackTech has exploited a buffer overflow vulnerability in Microsoft Internet Information Services (IIS) 6.0, CVE-2017-7269, in order to establish a new HTTP or command and control (C2) server.
10 more CVEs tied to this actor tracked in Mallory.
61 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as an associated threat actor in the detection annotation for exploitation of the public-facing PTC Windchill vulnerability CVE-2026-4681.
Named threat actor referenced in retrospective threat reporting.
Listed as a threat actor associated with the detection for Metasploit-based Atlassian Confluence exploitation activity.
Listed in the detection annotations as a threat actor associated with EFI volume mounting / installation-related behavior.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.