Threat actor · all actors
BlackTechG0098 state
🇨🇳 CN
aka BlackTech, Palmerworm, CIRCUIT PANDA, Temp.Overboard, HUAPI, G0098, T-APT-03, Manga Taurus, Red Djinn, Earth Hundun, Canary Typhoon, Mobwork, CAVERN CASTLE
Last updated: 2026-08-20
About this actor
BlackTech is a cyber espionage group operating against targets in East Asia, particularly Taiwan, and occasionally, Japan and Hong Kong. Based on the mutexes and domain names of some of their C&C servers, BlackTech’s campaigns are likely designed to steal their target’s technology. Following their activities and evolving tactics and techniques helped us uncover the proverbial red string of fate that connected three seemingly disparate campaigns: PLEAD, Shrouded Crossbow, and of late, Waterbear. PLEAD is an information theft campaign with a penchant for confidential documents. Active since 2012, it has so far targeted Taiwanese government agencies and private organizations. PLEAD’s toolset includes the self-named PLEAD backdoor and the DRIGO exfiltration tool. PLEAD uses spear-phishing emails to deliver and install their backdoor, either as an attachment or through links to cloud storage services. Some of the cloud storage accounts used to deliver PLEAD are also used as drop off points for exfiltrated documents stolen by DRIGO. PLEAD actors use a router scanner tool to scan for vulnerable routers, after which the attackers will enable the router’s VPN feature then register a machine as virtual server. This virtual server will be used either as a C&C server or an HTTP server that delivers PLEAD malware to their targets.
Source: MITRE ATT&CK
Names & naming systems
Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.
MITRE ATT&CKG-number catalogue id
Microsoftweather-system names
CrowdStrikenation-animal names
MandiantTEMP temporary cluster
Palo Alto Unit 42constellation names
Unclassifiedno scheme matched
How we know this
- Data origin
- MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
- Techniques
- MITRE ATT&CK STIX mappings — 20 ATT&CK techniques on file.
- Named victims
- None on file.
See how actor data is built for the full pipeline.
Activity timeline
No activity events recorded.
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
| No attributed CVEs. | |||||
T1021Remote Services ↗T1021.004SSH ↗T1036Masquerading ↗T1036.002Right-to-Left Override ↗T1046Network Service Discovery ↗T1106Native API ↗T1190Exploit Public-Facing Application ↗T1203Exploitation for Client Execution ↗T1204User Execution ↗T1204.001Malicious Link ↗T1204.002Malicious File ↗T1566Phishing ↗T1566.001Spearphishing Attachment ↗T1566.002Spearphishing Link ↗T1574Hijack Execution Flow ↗T1574.001DLL ↗T1588Obtain Capabilities ↗T1588.002Tool ↗T1588.003Code Signing Certificates ↗T1588.004Digital Certificates ↗
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
SI-4 | 15 / 20 | 75% |
CM-6 | 14 / 20 | 70% |
CM-2 | 13 / 20 | 65% |
SI-3 | 13 / 20 | 65% |
CA-7 | 11 / 20 | 55% |
AC-4 | 10 / 20 | 50% |
CM-7 | 10 / 20 | 50% |
SC-7 | 9 / 20 | 45% |
SI-2 | 9 / 20 | 45% |
AC-6 | 7 / 20 | 35% |
SC-44 | 7 / 20 | 35% |
SI-7 | 7 / 20 | 35% |
RA-5 | 6 / 20 | 30% |
SI-10 | 6 / 20 | 30% |
SI-8 | 6 / 20 | 30% |
Co-occurring actors
None.
Similar actors
Similar TTPs
- Ferocious Kitten 0.35
- Elderwood 0.28
- RedDelta Modified PlugX Infection Chain Operations 0.27
- Mofang 0.26
- Whitefly 0.25
Same nation-state
- Night Dragon 1.00
- FunnyDream 1.00
- Operation Wocao 1.00
- C0017 1.00
- Cutting Edge 1.00
Same category
- Night Dragon 1.00
- FunnyDream 1.00
- C0011 1.00
- Operation Wocao 1.00
- Operation Dream Job 1.00