Blackwood hijacks software updates to deploy NSPX30 – Week in security with Tony Anscombe
ID: 890da66b-f06c-5fda-80f7-fcf61657fb02
STIX ID: report--890da66b-f06c-5fda-80f7-fcf61657fb02
Feed Name: WeLiveSecurity (ESET Research)
Threat Score
ESET researchers disclosed that an APT named Blackwood deployed a sophisticated multistage implant, NSPX30, by performing adversary-in-the-middle hijacks of legitimate software update requests (e.g., Tencent QQ, WPS Office, Sogou Pinyin), targeting Chinese and Japanese companies and individuals in China, Japan, and the United Kingdom; the implant's lineage traces back to a small backdoor observed as early as 2005.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
