China-linked espionage group BlackTech—also tracked as Earth Hundun, Palmerworm, and Red Djinn—was tied to sustained intrusions across East Asia, with a heavy focus on Taiwan and Japan and victims spanning government, media, telecommunications, defense, academia, technology, semiconductors, manufacturing, and professional services. Reporting describes spearphishing campaigns using password-protected archives and malicious Excel macro files, alongside exploitation of internet-facing systems including ProxyLogon, CVE-2015-5119, and CVE-2017-7269, to gain initial access. In Japanese campaigns, researchers linked tools including Flagpro, BTSDoor, LAMICE, BUSYICE, TELESWORD, DELTABEEF, SELFMAKE, and SPIDERPIG to the actor, while earlier operations used PLEAD, DRIGO, Waterbear, and Shrouded Crossbow malware built around BIFROST/BIFROSE, KIVARS, and XBOW variants.
Researchers said BlackTech used modular, multi-stage malware to steal credentials, profile hosts, maintain persistence, and exfiltrate sensitive documents, including government, defense, budget, and foreign-affairs material. Flagpro was described as an early-stage downloader and credential stealer that could fetch second-stage payloads such as BTSDoor, while Waterbear operated as an in-memory backdoor and DRIGO exfiltrated data through Google services; separate analysis also identified a Linux ELF Bifrose variant, showing the group’s tooling extends beyond Windows. Investigations further uncovered exposed directories and overlapping command-and-control infrastructure tied to BlackTech, including malware controllers and exploit collections for routers, Citrix, MikroTik, VMware vRealize, Cisco RV devices, Hongdian routers, and Oracle WebLogic, while domain-tracking research showed the actor repeatedly reused registrant details, name servers, and tech-themed domains even as registrar choices shifted over time.

TTPs, infrastructure, and targeting history in one profile.
21 events from the most recent confirmed update back to the earliest known activity.
A Cyber and Ramen post reported that recent BlackTech infrastructure activity appeared to shift away from historical GoDaddy and domaincontrol patterns toward registrars such as PDR Ltd. and Vitalwerks.
Cyber and Ramen published an analysis of a malicious Excel macro document and dropped dwm.exe payload assessed as likely linked to BlackTech, though not definitively identified as Flagpro. The report detailed screenshot-taking functionality and infrastructure including centos.onthewifi[.]com resolving to 103.195.150[.]181, with ties to previously reported BlackTech-style C2 behavior.
NTT Security Japan published an analysis of Flagpro describing its use in attacks on Japanese organizations in defense, media, and telecommunications and detailing its phishing-based delivery and capabilities.
PwC published its 'Back to Black(Tech)' report analyzing recent BlackTech operations, including spearphishing with malicious Excel files, Flagpro, BTSDoor, and an exposed tool directory.
PwC said tweets in July 2021 also showed the open directory tied to BlackTech infrastructure and tooling.
NTT Security Japan reported that in July 2021 researchers observed a new Microsoft Foundation Class-based Flagpro variant, which they called Flagpro v2.0.
PwC reported that an analyzed Flagpro sample associated with BlackTech had a compile timestamp of 2021-06-22 07:01:31.
PwC said it pivoted from the BlackTech-linked domain update.centosupdates.com to tweets showing an open directory in May and July 2021.
Trend Micro linked BUSYICE to Earth Hundun/BlackTech because BUSYICE and TSCookie shared command-and-control infrastructure in April 2021, including a cited domain and IP address.
Trend Micro reported that a second 2021-attributed Earth Hundun/BlackTech campaign had been active since at least March 2021, using ProxyLogon exploitation or malware-bundled installers.
NTT Security Japan said a sample posted to an online service in October 2020 indicates Flagpro may already have been used in attacks by that time.
Trend Micro reported that one 2021-attributed Earth Hundun/BlackTech campaign had been active since at least September 2020, targeting Japanese media, telecommunications, defense, academia, and some individuals.
PwC reported that BlackTech used similar malicious Excel macro documents in 2018 to drop the TSCookie malware.
Trend Micro assessed that BTSDOOR appears to have been developed since at least 2018 based on compilation time and PDB data.
Trend Micro reported that PLEAD briefly used a fileless malware variant leveraging the leaked Hacking Team Flash exploit for CVE-2015-5119 embedded in crafted documents.
Infrastructure analysis found a spike in BlackTech-linked domain registrations in 2013, which the author says was largely due to the 'Four-Element Sword Engagement.'
Trend Micro reported that the PLEAD information-theft campaign has been active since 2012, targeting Taiwanese government agencies and private organizations.
Analysis cited in the ELF Bifrose article states that a group likely identified as BlackTech probably obtained the Bifrose source code around 2010 and enhanced it for its own campaigns.
Trend Micro reported that the Shrouded Crossbow campaign was first observed in 2010 and used BIFROST-derived backdoors against government contractors and enterprises.
The Bifrose/Bifrost backdoor malware family was first identified in the early 2000s as malware targeting Windows systems.
The ELF Bifrose analysis said a recent Linux Bifrose sample was highlighted in a tweet by @strinsert1Na on November 24 before the article's publication.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 21 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
8 references tracked. Mallory keeps watching after this page renders.
cyberandramen.net
Open sourcecyberandramen.net
Open sourcecyberandramen.net
Open sourceinsight-jp.nttsecurity.com
Open sourcetrendmicro.com
Open sourcevblocalhost.com
Open sourcedocuments.trendmicro.com
Open sourcejsac.jpcert.or.jp
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.