Waterbear is a long-running modular malware campaign and associated intrusion activity linked to the BlackTech cyber-espionage cluster. It has been used primarily against organizations in East Asia, with confirmed targeting of Taiwanese government entities and broader association with operations affecting Taiwan, Japan, and Hong Kong. Waterbear is assessed to function as a secondary backdoor or post-compromise framework used to maintain access after an initial intrusion, and its design allows operators to remotely extend functionality by delivering additional modules or payloads. Waterbear operations have relied on prior footholds, residual malware from earlier compromises, and stolen credentials to regain or expand access inside victim environments. In observed intrusions against Taiwanese government agencies, operators exploited a vulnerability in trusted data loss prevention software to perform DLL hijacking and execute Waterbear with elevated privileges. The malware then injected shellcode into Windows system services and used a loader to deploy additional malicious packages in memory. Waterbear has also been described as supporting lateral movement and payload decryption and execution through its loader component. The malware incorporates multiple defense-evasion features, including Heaven's Gate to execute 64-bit code from ostensibly 32-bit processes, RC4-encrypted payloads, padding around shellcode using Kernel32.dll content, and artificially inflated binaries intended to hinder analysis and evade file-based detection. Later variants have used patched server applications as loader components, with the main backdoor loaded from encrypted local content or retrieved from command and control. Waterbear is one of several campaigns commonly associated with BlackTech, alongside PLEAD and Shrouded Crossbow. These operations have been linked through overlapping victimology, shared infrastructure, similar delivery tradecraft, and the presence of multiple related malware families on the same targets. The broader activity is consistent with cyber espionage focused on theft of sensitive government, defense, foreign affairs, budgetary, contractual, and other internal documents.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting sophisticated intrusions against Taiwanese government agencies, using previously implanted malware on compromised servers, exploiting a DLP tool weakness for DLL hijacking, injecting shellcode into Windows services, and using evasion techniques such as Heaven's Gate and RC4-encrypted payloads.
Modular backdoor campaign likely used as a secondary payload to maintain persistence after attackers gain access to target environments.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.