IconDown is a Windows downloader associated with the China-linked espionage group BlackTech. It has been used in intrusions against Japanese organizations and is part of a broader BlackTech malware ecosystem that also includes TSCookie and PLEAD. Reporting has also linked related distribution activity to abuse of the ASUS WebStorage update mechanism.
IconDown retrieves a remote file over HTTP, searches the downloaded content for a fixed marker, extracts an RC4 key from the file, and uses that key to decrypt embedded data. The decrypted content contains configuration values and a PE payload. IconDown then writes the payload to disk using either configured or fallback locations and, depending on the configuration, may execute the payload through the Windows command interpreter, terminate, or both. This behavior makes IconDown a staging component used to deliver and launch additional malware rather than a full-featured backdoor itself.
The malware is notable for its simple but structured payload-unpacking workflow: remote retrieval, signature validation, RC4-based decryption, payload extraction, filesystem write, and optional execution. Its role in BlackTech operations aligns with the group’s long-running focus on stealthy access, modular tooling, and follow-on deployment of additional implants in espionage campaigns targeting organizations in Japan and other parts of East Asia.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
Based on the configuration value, it determines the path to save the file from the following: File name contained in the configuration of the downloaded file %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\slui.exe
Specifically, upon gaining an initial foothold into a target network and gaining administrator access to network edge devices, BlackTech cyber actors often modify the firmware to hide their activity across the edge devices to further maintain persistence in the network.
Specifically, upon gaining an initial foothold into a target network and gaining administrator access to network edge devices, BlackTech cyber actors often modify the firmware to hide their activity across the edge devices to further maintain persistence in the network.
Specifically, upon gaining an initial foothold into a target network and gaining administrator access to network edge devices, BlackTech cyber actors often modify the firmware to hide their activity across the edge devices to further maintain persistence in the network.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom malware listed by the advisory as part of BlackTech’s router and network intrusion toolkit.
Mentioned as malware used by BlackTech.
Downloader malware used by BlackTech that retrieves a file from a specific site, searches for a signature in the downloaded content, extracts a 256-byte RC4 key, decrypts embedded data, reconstructs a PE payload, writes it to disk, and executes it based on configuration values.
Named as one of Earth Hundun/BlackTech's tools in the actor profile timeline.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.