NSPX30 is a modular Windows implant associated with the China-aligned Blackwood espionage cluster and assessed to have lineage connected to older tooling such as DCM/Dark Specter and Project Wood. Activity linked to this malware family spans many years, with known samples ranging from the mid-2000s through 2024. It is notable for being deployed through adversary-in-the-middle hijacking of legitimate software update mechanisms rather than conventional phishing-based delivery.
Blackwood has used network interception to tamper with update traffic for widely used Chinese software, causing legitimate applications to retrieve an NSPX30 dropper over unencrypted channels. Reported abuse has involved update workflows for Tencent QQ, Sogou Pinyin, and WPS Office. The dropper may be delivered as a DLL or executable, including within an archive when needed.
NSPX30 establishes persistence by installing a malicious Winsock Namespace Provider DLL so that its loader is automatically invoked by processes using Winsock. The malware is highly modular and includes loader, orchestrator, backdoor, and plugin components. The orchestrator can fetch the backdoor, drop and load additional components, perform allowlisting-related actions, and manage plugin execution. The backdoor supports system information collection, plugin extraction and loading, remote retrieval of additional plugins, command-and-control communications, and exfiltration of collected data.
Observed plugins indicate a broad post-compromise feature set, including theft of application data, decryption of protected local data stores, SQL-based access to stored information, in-memory function hooking, and audio-device interaction through multimedia APIs. Reporting also describes defense-evasion behavior aimed at bypassing or weakening protections from multiple Chinese security products as well as Microsoft Defender. Some of these allowlisting-bypass techniques overlap with tradecraft seen in other China-linked operations.
Victimology associated with Blackwood and NSPX30 includes individuals and organizations in China, Japan, and the United Kingdom, including manufacturing-related entities. The malware is part of a broader pattern of China-aligned threat activity using adversary-in-the-middle techniques to selectively compromise targets through trusted software-update channels.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Implant deployed via abuse of Sogou Pinyin’s update process (malicious update delivery technique).
Implant delivered by abusing Sogou Pinyin’s software update mechanism.
An implant referenced in connection with Blackwood attacks against telecom operators, indicating use as a covert access/persistence tool in telecom-focused intrusions.
A sophisticated adversary-in-the-middle-enabled modular implant/backdoor delivered via hijacked software updates. It uses a dropper, persists as a Winsock Namespace Package DLL, loads multiple components and plugins, communicates through attacker-controlled AitM infrastructure, gathers system information, downloads and loads plugins, and exfiltrates collected data.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.