logo

RADIO_PANDA__2017__appendix-following-the-trail-of-blacktechs-cyber-espionage-campaigns.pdf

ID: 8158441c-08e9-4d2b-8ed7-6b7dbebe28ee

STIX ID: report--8158441c-08e9-4d2b-8ed7-6b7dbebe28ee

Threat Score

82/100

Uploaded: 2026-08-19

Published Date: 2017-06-21

Last Modified Date: 2017-06-21

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Trend Micro's technical analysis of the BlackTech / Shrouded Crossbow espionage campaign describes multiple malware families (PLEAD, DRIGO, Waterbear, BIFROST variants including KIVARS and XBOW), their delivery (spear-phishing, cloud-hosted payloads, router compromise, exploited IIS/CVE and a Hacking Team exploit for fileless execution), C2 protocols, capabilities (remote commands, Google Drive/Gmail-based exfiltration, in-memory loaders), and provides extensive IoCs (SHA256 hashes, C2 domains and IPs) to support detection and response.