logo

Blackwood hackers hijack WPS Office update to install malware

ID: c4aa5e78-80c1-5bb3-a715-ea2989db4b71

STIX ID: report--c4aa5e78-80c1-5bb3-a715-ea2989db4b71

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2024-01-25

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Blackwood is a previously untracked, likely Chinese-aligned APT that has used the NSPX30 multistage implant since at least 2018 to conduct cyberespionage against organizations and individuals in China, Japan, and the UK. NSPX30 evolved from a 2005 backdoor lineage, features extensive data-collection and evasion capabilities, and is delivered by adversary-in-the-middle interception of unencrypted software update traffic (e.g., WPS Office, Tencent QQ, Sogou Pinyin); ESET provides technical analysis and IOCs to help defenders detect and mitigate the campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.