Researchers tied multiple malware families used by BlackTech to intrusions against organizations in Japan and elsewhere, showing the group operating across both Windows and Linux systems. JPCERT/CC reported that the IconDown downloader fetched data from attacker-controlled hosts, searched for a fixed 9-byte signature, extracted a 256-byte RC4 key, decrypted embedded configuration data and a PE payload, then wrote the payload to disk and optionally launched it via cmd.exe. Related reporting from ESET said BlackTech also abused the ASUS WebStorage update mechanism in router-level man-in-the-middle attacks to distribute PLEAD malware, extending the group’s delivery options beyond direct malware staging.

TTPs, infrastructure, and targeting history in one profile.
9 events from the most recent confirmed update back to the earliest known activity.
Cyber and Ramen analyzed an updated ELF_PLEAD backdoor sample, describing a dynamically linked 64-bit Linux executable that used SSL, supported file operations, remote shell, and proxying, and contained hardcoded C2 IP 168.95.1.1. The post also contrasted the sample with earlier public reporting and published the sample hash as an IOC.
JPCERT/CC published analysis of ELF_PLEAD, a Linux malware family used by BlackTech, and described its similarities to the Windows PLEAD module. The report detailed its RC4-encrypted configuration, custom C2 protocol, and command groups for file management, transfer, remote shell, port forwarding, and malware control.
Cyber and Ramen says TeamT5 reported in April 2020 on an intrusion at a Taiwan academic institution attributed to BlackTech. The intrusion reportedly used Ghostcat (CVE-2020-1938) for initial access and involved a Unix variant of the Bifrose/Bifrost backdoor.
Cyber and Ramen states that JPCERT identified a Linux variant of BlackTech's TSCookie loader in March 2020. This marked public reporting of BlackTech Linux-focused tooling beyond its Windows malware families.
JPCERT/CC published an analysis of IconDown, confirming BlackTech used the downloader in attacks against Japanese organizations. The report detailed how IconDown retrieved a file, extracted an RC4 key and payload, and could write and execute the resulting PE file, while also publishing sample hashes and C2-related indicators.
ESET published reporting that PLEAD malware was distributed through man-in-the-middle attacks abusing the ASUS WebStorage update function. Later JPCERT/CC reporting cited this distribution method in related BlackTech activity.
JPCERT/CC reported that in May 2019, TSCookie samples used in attacks had been modified to correct the configuration copy size from 0x8D4 to 0x1000, fixing a previously documented decoding bug. The update also resolved a problem that prevented the malware from reconnecting to its command-and-control server for several days, and JPCERT/CC published sample hashes and associated C2 servers.
JPCERT/CC said an updated version of the TSCookie malware, believed to be used by BlackTech, was observed in attacks around August 2018. The update changed C2 communications from the HTTP Cookie header to encrypted URL parameters and introduced a configuration-reading bug.
Cyber and Ramen says Intezer tweeted in late March 2021 a hash for what was described as a fully undetectable version of ELF_PLEAD. This indicated continued evolution of BlackTech's Linux backdoor tooling.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 19 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
6 references tracked. Mallory keeps watching after this page renders.
cyberandramen.net
Open sourceblogs.jpcert.or.jp
Open sourceblogs.jpcert.or.jp
Open sourceblogs.jpcert.or.jp
Open sourcewelivesecurity.com
Open sourceblogs.jpcert.or.jp
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.