Hacker groupG0098

BlackTech

Also tracked as Palmerworm

BlackTech is a suspected Chinese cyber espionage group that has primarily targeted organizations in East Asia--particularly Taiwan, Japan, and Hong Kong--and the US since at least 2013. BlackTech has used a combination of custom malware, dual-use tools, and living off the land tactics to compromise media, construction, engineering, electronics, and financial company networks.

Known attack methods
14
Origin
China
Motive
Espionage
First seen
2013
Source
MITRE ATT&CK

How they break in

Techniques MITRE has documented this group using, mapped onto the ATT&CK matrix. Each one is a behaviour you can look for in your own logs, and a control you can test.

Malware

Families MITRE records this group deploying. Detection names for these are a reasonable place to start.

FlagproKivarsPLEADTSCookieWaterbear

Tools

Legitimate or dual-use software the group is documented using. Most of it is software your own administrators use too, which is the point.

PsExec