logo

BlackEnergy & Quedagh: The convergence of crimeware and APT attacks

ID: 604dc548-91a7-4b7f-b4b6-5081310152e9

STIX ID: report--604dc548-91a7-4b7f-b4b6-5081310152e9

Threat Score

68/100

Uploaded: 2026-08-19

Published Date: 2014-09-24

Last Modified Date: 2014-09-24

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report analyzes the BlackEnergy toolkit and its Quedagh-customized variants (BlackEnergy 1–3), describing how the malware infects targets through Trojanized apps, exploit documents, and droppers; how it persists via drivers or startup links, and how it exfiltrates information through an information-stealing plugin, with timeline context from 2007–2014 and observed Ukrainian government targeting, proxy usage, and driver-signing bypass techniques that enable stealthy operations by a suspected threat actor/APT group.