Threat Actor ๐จ๐ณ China
Blackwood
Blackwood is a China-aligned APT group that has been active since at least 2018. They primarily engage in cyberespionage operations targeting individuals and companies in China, Japan, and the United Kingdom. Blackwood utilizes sophisticated techniques such as adversary-in-the-middle attacks to deliver their custom implant, NSPX30, through updates of legitimate software. They also have the capability to hide the location of their command and control servers by intercepting traffic generated by the implant.
Indicators of Compromise 18
Domain asdfafadafg[.]online Domain cloud[.]g-drive[.]cam Domain drivegoogel[.]cam Domain googeldrive[.]cam Domain googelmeet[.]online Domain meetonline[.]cam SHA-256 3fd810a3aa0039993393741b32287c367a9a5037a41e826906440887cdd3ed13 SHA-256 53f35e49eb9b271fd8cbcd3daacb525328dbf159a03dbd1c7adebe0363daa402 SHA-256 6e7d9b33f1e72ea1ede71373a604ecdb060dab7d42055179c1eede9ecd1fd239 SHA-256 76273382e4252c1f60a2251141e108942494409c759358320735891762c0682e SHA-256 7cc571aca6d8715d9aaad3d83e1bcd30467565d583db1dfe73697c5d00a1f875 SHA-256 d3561bd4aad003dc3e08157b0891860bb496b80cd6e44901692e08ab1d4e8260 SHA-256 f5b12772db6817f7a765a6fe7565fd3d4f87edc28e42fe3ec0244a372a410fc9 SHA-256 f5ba1645694c62f527ed6ceda8c68a5c3dd92b4032439167e8e937e72803b4bd IP 38[.]180[.]136[.]127 IP 65[.]109[.]214[.]145 IP 87[.]248[.]129[.]239 IP 91[.]107[.]156[.]29