logo

NSPX30: A sophisticated AitM-enabled implant evolving since 2005

ID: c79db6b1-4a12-5928-8b3a-461fe902dcfd

STIX ID: report--c79db6b1-4a12-5928-8b3a-461fe902dcfd

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
90/100

Date Published: 2024-01-24

Date Updated: 2026-05-01

...
...

ESET details Blackwood, a China-aligned APT active since at least 2018, which deploys a multistage implant called NSPX30 via adversary-in-the-middle interception of unencrypted software updates for popular Chinese applications; NSPX30 uses a persistent Winsock provider, modular plugins for credential/audio/screenshot/keylogging collection, and network interception (HTTP/DNS/UDP) to hide C2 and exfiltrate data, with IOCs and MITRE ATT&CK mappings provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.