logo

China-backed Hackers Hijack Software Updates to Implant "NSPX30" Spyware

ID: a5144a82-603c-5e19-9db6-b0f910b33b40

STIX ID: report--a5144a82-603c-5e19-9db6-b0f910b33b40

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2024-01-25

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

A previously undocumented China-aligned APT tracked as Blackwood is conducting adversary-in-the-middle (AitM) attacks that hijack unencrypted software update requests for legitimate applications (e.g., Tencent QQ, WPS Office, Sogou Pinyin) to deliver a multistage implant called NSPX30. NSPX30 is a sophisticated framework (dropper, installers, loaders, orchestrator, backdoor and plugins) that leverages packet interception, DLL side‑loading, network implants, passive UDP listeners and DNS-like exfiltration to hide infrastructure and evade Chinese anti‑malware allowlisting; observed targets include manufacturing, trading and engineering organizations and individuals in China, Japan and the U.K.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.