logo

BlackTech__2021__unit42.paloaltonetworks.com-BendyBear_Novel_Chinese_Shellcode_Linked_With_Cyber_Espionage_Group_BlackTech.pdf

ID: 06fe2a84-a670-4709-bc65-a974623d9f9b

STIX ID: report--06fe2a84-a670-4709-bc65-a974623d9f9b

Threat Score

85/100

Uploaded: 2026-08-14

Published Date: 2021-02-10

Last Modified Date: 2021-02-10

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
BendyBear is a sophisticated, >10KB x64 stage‑0 shellcode downloader attributed to the BlackTech espionage group; it uses modified RC4, per‑session keys, polymorphic and anti‑analysis techniques, registry‑based configuration and in‑memory PE loading to stealthily retrieve a stage‑2 implant from C2. The Unit 42 analysis includes protocol and cryptographic details, sample hashes and domains, comparisons to WaterBear, and mitigation guidance for detection and blocking.