Blackgear__2016__TrendLabs_Security_Intelligence_BlogBLACKGEAR_Espionage_Campaign_Evolves_Adds_Japan_To_Target_List_-_TrendLabs_Security_Intelligence_Blog.pdf
ID: 2c5ebb1a-6921-4a69-8fea-b7466904afc9
STIX ID: report--2c5ebb1a-6921-4a69-8fea-b7466904afc9
Threat Score
75/100
Uploaded: 2026-08-14
Published Date: 2016-12-20
Last Modified Date: 2016-12-20
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
BLACKGEAR is a sustained espionage campaign analyzed by Trend Micro that uses a three-stage malware chain (binders → downloaders → backdoors) and an unusual C2 retrieval method: encrypted configuration data hidden inside blog/microblog posts. The report details technical decryption routines (modified TEA and DES/Base64), persistence mechanisms, links between multiple families (BKDR_ELIRKS, BKDR_YMALR, TSPY_RAMNY, TSPY_YMALRMINI), an expansion of targeting into Japan, and publishes extensive IOCs (hashes and C2 indicators) to help defenders detect and remediate infections.
