China-backed Hackers Hijack Software Updates to Implant "NSPX30" Spyware
ID: a5144a82-603c-5e19-9db6-b0f910b33b40
STIX ID: report--a5144a82-603c-5e19-9db6-b0f910b33b40
Feed Name: The Hacker News
A previously undocumented China-aligned APT tracked as Blackwood is conducting adversary-in-the-middle (AitM) attacks that hijack unencrypted software update requests for legitimate applications (e.g., Tencent QQ, WPS Office, Sogou Pinyin) to deliver a multistage implant called NSPX30. NSPX30 is a sophisticated framework (dropper, installers, loaders, orchestrator, backdoor and plugins) that leverages packet interception, DLL side‑loading, network implants, passive UDP listeners and DNS-like exfiltration to hide infrastructure and evade Chinese anti‑malware allowlisting; observed targets include manufacturing, trading and engineering organizations and individuals in China, Japan and the U.K.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
