BLACKCOFFEE, also referred to as ZoxPNG, is a Windows malware family associated primarily with Chinese espionage activity and most consistently linked to APT17, with additional reporting connecting its use to APT41 and operations overlapping with other China-linked clusters. It has been described as part of the ZoxRPC/ZoxPNG lineage and as a recurring tool in long-running intrusion campaigns against government and enterprise targets, including activity affecting Japanese organizations.
Functionally, BLACKCOFFEE provides remote access capabilities consistent with a backdoor or remote access trojan. Reported behaviors include process discovery, file and directory enumeration, file deletion, and creation of a reverse shell for operator command execution. It has also used dead-drop resolver techniques to obtain command-and-control information from legitimate web content, including Microsoft TechNet, and has disguised command-and-control traffic as normal access to trusted services such as GitHub to blend with benign network activity and complicate detection.
The malware has appeared alongside other China-linked tooling such as Derusbi, PlugX, Ghost RAT, HiKit, and China Chopper in intrusion sets attributed to espionage operators. Reporting ties BLACKCOFFEE closely to APT17 tradecraft and infrastructure patterns, while some analyses note reuse by APT41, suggesting either tool sharing, common developers, or overlap across contractor-style ecosystems supporting Chinese state interests. Its observed behaviors align with post-compromise reconnaissance, interactive control, and operational cleanup on infected hosts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Axiom Derusbi 9002 RAT BLACKCOFFEE Derusbi Ghost RAT HiKit PlugX ZXShell APT17
Mr. Zeng is credited with creating a specific exploit of the public vulnerability MS08-067. This is associated with the ZoxPRC which evolved into BLACKCOFFEE malware, a hallmark of APT17 and Zeng specifically. APT41 are using this same malware in their operations.
Mr. Zeng is credited with creating a specific exploit of the public vulnerability MS08-067. This is associated with the ZoxPRC which evolved into BLACKCOFFEE malware, a hallmark of APT17 and Zeng specifically. APT41 are using this same malware in their operations.
Tools Nanhaishu, Orz, SeDll, Cobalt Strike, GreenCrash, AIRBREAK, BlackCoffee, China Chopper, FUSIONBLAZE, HOMEFRY, MURKYTOP, Metasploit / Meterpreter, ScanBox, Derusbi Trojan, Derusbi, Metasploit
…exploit framework ZoxRPC. ZoxRPC evolved into ZoxPNG (also known as BLACK-COFFEE), a malware which MITRE ATT&CK attributed to APT17 and APT41…
15 distinct techniques documented for this family, organized by ATT&CK tactic.
Numerous entries state malware can create a remote shell or reverse shell, for example 4H RAT, BLACKCOFFEE, DarkComet, PlugX, QuasarRAT, and others. | The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
"BLACKCOFFEE has also obfuscated its C2 traffic as normal traffic to sites such as Github."
The adversaries had communicated to both Dropbox and Pastebin. APT28 has used Google Drive for C2. APT37 leverages social networking sites and cloud platforms (AOL, Twitter, Yandex, Mediafire, pCloud, Dropbox, and Box) for C2.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware family associated with APT17 that evolved from ZoxPRC and is described as being used by APT41 as well; the content links it to an MS08-067 exploit and Chinese APT operations.
Backdoor malware capable of deleting files.
Backdoor malware capable of discovering processes on a compromised host.
Backdoor that disguises command-and-control traffic as benign traffic to legitimate services (e.g., GitHub).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.