logo

BlackTech__2021__Malware_Gh0stTimes_Used_by_BlackTech_-_JPCERT_CC_Eyes_JPCERT_Coordination_Center_official_Blog.pdf

ID: b265cf03-8025-4194-8ad0-198c1f774d51

STIX ID: report--b265cf03-8025-4194-8ad0-198c1f774d51

Threat Score

85/100

Uploaded: 2026-08-14

Published Date: 2021-10-05

Last Modified Date: 2021-10-05

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
JPCERT/CC provides a technical analysis of Gh0stTimes (a Ghost RAT derivative) used by the BlackTech APT: detailing its custom C2 protocol (ID/key exchange, XOR/RC4+zlib payloads), command modules (FileManager, ShellManager, PortmapManager, UltraPortmapManager), control-panel screenshots ("Times v1.2"), dummy code samples, Python decoding example, and an appendix of IoCs (C2 domains/IPs and malware hashes) to aid detection and response.