logo

Newly ID'ed Chinese APT Hides Backdoor in Software Updates

ID: f64d8e0b-e26a-540c-a86e-2d6b804932c7

STIX ID: report--f64d8e0b-e26a-540c-a86e-2d6b804932c7

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2024-01-26

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Since 2018 ESET has identified a previously unknown Chinese APT named Blackwood that deploys a highly evolved multistage backdoor family (NSPX30) in AitM attacks to silently inject malware into unencrypted software updates (notably WPS Office, QQ, and Sogou) via suspected network implants; NSPX30 enables extensive espionage (file/credential theft, keystrokes, screenshots, chat/audio capture), command-and-control concealment, and persistence. Recommended defenses include endpoint detection tuned for NSPX30, monitoring for anomalous update deliveries and AitM activity (e.g., ARP poisoning), network segmentation, and mitigations for IPv6 SLAAC exploits.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.