Flagpro is a malware family used by the China-linked threat actor BlackTech. According to the provided content, BlackTech described Flagpro as malware used in the initial stage of attacks to investigate a target environment, download a second-stage payload, and execute it. It has been distributed via spearphishing email attachments and can execute malicious VBA macros embedded in .xlsm files, relying on user interaction to trigger infection. Reported reconnaissance and discovery behavior includes checking whether the target system is using Japanese, Taiwanese, or English by detecting specific Windows Security and Internet Explorer dialogs, checking the name of the window displayed on the system, and executing commands such as whoami and net view on compromised hosts. Flagpro can close specific Windows Security and Internet Explorer dialog boxes to mask external connections. Its command-and-control communications are described as bidirectional and Base64-encoded, and the malware has exfiltrated data to its C2 server. The content also places Flagpro among multiple custom malware families associated with BlackTech activity targeting organizations in the United States and Japan, including government and private-sector entities across industrial, technology, media, electronics, and telecommunications sectors, with observed targeting of multiple Cisco versions in broader BlackTech operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
BlackTech uses a new malware for these attack cases. We call it “Flagpro”. Flagpro is used in the initial stage of attacks to investigate target’s environment, download a second stage malware and execute it.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
admin@338 has attempted to get victims to launch malicious Microsoft Word attachments delivered via spearphishing emails... APT28 attempted to get users to click on Microsoft Office attachments containing malicious macro scripts... Dragonfly has used various forms of spearphishing in attempts to get users to open malicious attachments.
Following list indicates Flagpro’s main functions: ... Execute OS commands and send the results
The archived file includes an xlsm format file and it contains a malicious macro. If a user activates the macro, a malware will be dropped.
The content repeatedly describes victims being lured into opening malicious attachments, enabling macros, launching installers, clicking embedded files/links, or otherwise directly executing malicious content.
Sandworm Team leveraged Microsoft Office attachments which contained malicious macros that were automatically executed once the user permitted them... APT29 has used various forms of spearphishing attempting to get a user to open attachments... DarkGate is distributed through phishing links to VBS or MSI objects requiring user interaction for execution.
Numerous malware families and threat groups are described as achieving persistence by adding values under Run/RunOnce/Policies\Explorer\Run Registry keys or by placing shortcuts/files in the Windows Startup folder.
Specifically, upon gaining an initial foothold into a target network and gaining administrator access to network edge devices, BlackTech cyber actors often modify the firmware to hide their activity across the edge devices to further maintain persistence in the network.
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
Specifically, upon gaining an initial foothold into a target network and gaining administrator access to network edge devices, BlackTech cyber actors often modify the firmware to hide their activity across the edge devices to further maintain persistence in the network.
The content references collection of credential material from local systems, including "Bumblebee can capture and compress stolen credentials from the Registry and volume shadow copies," "GALLIUM collected ... password hashes from the SAM hive in the Registry," and "Windigo has used a script to gather credentials in files left on disk by OpenSSH backdoors."
Specifically, upon gaining an initial foothold into a target network and gaining administrator access to network edge devices, BlackTech cyber actors often modify the firmware to hide their activity across the edge devices to further maintain persistence in the network.
Multiple malware families are described as identifying/enumerating open windows or capturing foreground window titles (e.g., via EnumWindows, GetForegroundWindow, GetWindowText) to understand user activity and provide context for keylogging/screencapture.
The content repeatedly describes malware and threat actors using commands and APIs such as ipconfig /all, ifconfig, arp -a, route print, nbtstat, netsh, GetAdaptersInfo, and GetIpNetTable to gather IP addresses, MAC addresses, DNS, DHCP, gateways, routing tables, ARP cache, proxy settings, domains, and network adapter/interface details.
During the 2015 Ukraine Electric Power Attack, Sandworm Team remotely discovered systems over LAN connections. OT systems were visible from the IT network as well, giving adversaries the ability to discover operational assets.
The content repeatedly describes malware and threat actors collecting usernames, identifying logged-in users, running whoami/query user/quser, checking whether the current user is an administrator, enumerating user sessions, and gathering account details from compromised hosts.
The content repeatedly describes malware and threat actors obtaining lists of running processes, using utilities such as tasklist, ps, WMI, Get-Process, CreateToolhelp32Snapshot, EnumProcesses, and similar APIs/commands to enumerate active processes on victim systems.
Avaddon checks for specific keyboard layouts and OS languages to avoid targeting Commonwealth of Independent States (CIS) entities... Bazar can perform a check to ensure that the operating system's keyboard and language settings are not set to Russian... Clop has checked the keyboard language using the GetKeyboardLayout() function... Ryuk has been observed to query the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls\Language and the value InstallLanguage.
The content repeatedly describes threat actors and malware using HTTP and HTTPS for command and control, such as: "Sandworm Team used BlackEnergy to communicate between compromised hosts and their command-and-control servers via HTTP post requests."
Flagpro is used in the initial stage of attacks to investigate target’s environment, download a second stage malware and execute it... Regarding to downloading and executing a tool, Flagpro stores the downloaded file in file path “%Temp%\~MY[0-9A-F].tmp” first. Then, Flagpro adds extension “.exe” to the name of stored file and executes the file.
ADVSTORESHELL exfiltrates data over the same channel used for C2... Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers... numerous malware and groups sent victim data, files, credentials, or host information over existing C2 channels.
37 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom malware family cited as part of BlackTech’s toolkit for stealthy access and persistence.
Flagpro is an initial-stage malware used in spear-phishing campaigns. It is dropped via malicious macro-enabled XLSM files, persists via the startup folder often as dwm.exe, communicates with a C&C server over HTTP using Internet Explorer COM objects, executes OS commands, collects Windows authentication information, and downloads and executes second-stage payloads.
Malware that identifies system language by detecting specific localized Windows Security and Internet Explorer dialogs.
Malware that fingerprints target language environment by detecting localized Windows and Internet Explorer dialogs.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.