BendyBear is a sophisticated Windows x64 stage-zero shellcode implant associated with the WaterBear malware lineage and linked to BlackTech, a China-aligned cyber-espionage group. Its primary role is to establish covert command-and-control communications and download a more capable follow-on implant for in-memory execution. BlackTech operations have historically targeted organizations in East Asia as well as entities in the United States and Japan, including government, media, telecommunications, technology, electronics, industrial, and related sectors.
BendyBear is notable for unusually large and complex shellcode that incorporates multiple stealth and anti-analysis features. It uses runtime decryption of internal function blocks with XOR-based protection, byte randomization, and polymorphic self-modifying behavior to hinder static analysis and signature-based detection. It also performs timing-based and debugger-related checks, including use of GetTickCount and inspection of process environment structures, to identify analysis environments. The implant dynamically resolves Windows API functions through shellcode API hashing and loads required libraries at runtime.
For host profiling and configuration, BendyBear can determine local system time and query Windows Registry data, including values under the current user console configuration, to derive operational parameters. For network communications, it uses a custom protocol over TCP port 443 designed to blend with common encrypted traffic. Its command-and-control channel employs modified RC4-style encryption together with XOR-encrypted chunks and per-connection session keys, providing authenticated and obfuscated communications.
BendyBear’s supported tasking is narrowly focused on payload retrieval. It downloads encrypted payload chunks from command and control, decrypts them in memory, validates the retrieved content as a Windows DLL, and then loads the module directly in memory in a manner intended to reduce normal module-tracking visibility. This makes BendyBear best characterized as an advanced downloader-stage implant used to bootstrap more feature-rich espionage tooling.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
Specifically, upon gaining an initial foothold into a target network and gaining administrator access to network edge devices, BlackTech cyber actors often modify the firmware to hide their activity across the edge devices to further maintain persistence in the network.
BitPaymer has used dynamic API resolution to avoid identifiable strings within the binary, including RegEnumKeyW.
Transmits payloads in modified RC4-encrypted chunks... Table 1 ... Payloads in modified RC4-encrypted chunks ... T1027.002: Obfuscated Files or Information: Software Packing
Examples throughout the content include 'encrypted payloads decrypted and executed in memory,' 'encrypts its configuration file,' 'AES-encrypted resource,' 'RC4 encrypted embedded scripts,' and 'payload includes an encrypted main component.'
Specifically, upon gaining an initial foothold into a target network and gaining administrator access to network edge devices, BlackTech cyber actors often modify the firmware to hide their activity across the edge devices to further maintain persistence in the network.
Specifically, upon gaining an initial foothold into a target network and gaining administrator access to network edge devices, BlackTech cyber actors often modify the firmware to hide their activity across the edge devices to further maintain persistence in the network.
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
The shellcode begins by locating the target’s Process Environment Block (PEB) to check if it’s currently being debugged... This routine is performed 52 times... Table 1 ... T1082: System Information Discovery
The content repeatedly describes malware and threat actors collecting the current date, time, or time zone from victim systems, including examples such as "The net time command can be used... to determine the local or remote system time" and commands like "net time \\hostname" and "w32tm /tz".
Many entries describe XOR, XOR/ADD, bitwise NOT and XOR, ROR plus XOR, hexadecimal encoding after encryption, and custom encoding/obfuscation of HTTP traffic or beacons.
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom malware observed in BlackTech operations targeting Cisco routers and enterprise networks.
Malware that loads and executes modules while resolving Windows APIs through shellcode API hashing.
Backdoor that uses modified RC4 and XOR-encrypted chunks for C2 over port 443.
Backdoor malware capable of determining local time on compromised systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.