China-Linked Blackwood APT Deploys Advanced NSPX30 Backdoor in Cyberespionage
ID: 903407a8-2461-5321-96a9-ecc1fb0f397a
STIX ID: report--903407a8-2461-5321-96a9-ecc1fb0f397a
Feed Name: HackRead
Threat Score
ESET researchers identified a China-aligned APT dubbed Blackwood using a sophisticated, multistage backdoor called NSPX30—evolving from samples dating to 2005—to conduct targeted cyberespionage in China, Japan, and the UK; NSPX30 leverages AiTM interception of unencrypted software update traffic (e.g., Tencent QQ, Sogou Pinyin, WPS Office) to establish covert channels, steal data (keystrokes, screenshots, system/network info), deploy modular plugins, and persist or re-compromise victims.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
