logo

Blackwood hijacks software updates to deploy NSPX30 – Week in security with Tony Anscombe

ID: 890da66b-f06c-5fda-80f7-fcf61657fb02

STIX ID: report--890da66b-f06c-5fda-80f7-fcf61657fb02

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
85/100

Date Published: 2024-01-26

Date Updated: 2026-05-01

...
...

ESET researchers disclosed that an APT named Blackwood deployed a sophisticated multistage implant, NSPX30, by performing adversary-in-the-middle hijacks of legitimate software update requests (e.g., Tencent QQ, WPS Office, Sogou Pinyin), targeting Chinese and Japanese companies and individuals in China, Japan, and the United Kingdom; the implant's lineage traces back to a small backdoor observed as early as 2005.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.