logo

China-Linked Blackwood APT Deploys Advanced NSPX30 Backdoor in Cyberespionage

ID: 903407a8-2461-5321-96a9-ecc1fb0f397a

STIX ID: report--903407a8-2461-5321-96a9-ecc1fb0f397a

Feed Name: HackRead

Threat Score
85/100

Date Published: 2024-01-26

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

ESET researchers identified a China-aligned APT dubbed Blackwood using a sophisticated, multistage backdoor called NSPX30—evolving from samples dating to 2005—to conduct targeted cyberespionage in China, Japan, and the UK; NSPX30 leverages AiTM interception of unencrypted software update traffic (e.g., Tencent QQ, Sogou Pinyin, WPS Office) to establish covert channels, steal data (keystrokes, screenshots, system/network info), deploy modular plugins, and persist or re-compromise victims.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.