2025年に確認されたBlackTechのマルウェアKivarsの亜種
ID: 89a5dc55-7a49-5eee-9f7c-281226cdbca0
STIX ID: report--89a5dc55-7a49-5eee-9f7c-281226cdbca0
Feed Name: IIJ Security Diary
The report analyzes Kivars — a backdoor loader attributed to the China-linked APT BlackTech — observed in 2025 and targeting organizations (notably in Japan and Taiwan). It describes Kivars' execution flow (loader + encrypted DLL executed in memory), a customized RC4 decryption routine, mutex and persistence behavior, proxy-capable C2 communications with a hardcoded RC4 key, implemented remote commands, and operational details indicating use after privilege escalation; the publication includes a configuration-extraction tool and a detailed set of IoCs (file hashes, domains, and IPs) to support detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
