Copy of Back to Black(Tech) - VB Localhost
ID: dcf4c89a-d5d2-44c0-bb4a-4e75113d4f66
STIX ID: report--dcf4c89a-d5d2-44c0-bb4a-4e75113d4f66
Threat Score
85/100
Uploaded: 2026-08-14
Published Date: 2026-02-13
Last Modified Date: 2026-02-13
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This PwC report analyzes the BlackTech APT: documenting spearphishing delivery, VBA macro droppers, multiple implants (Flagpro, BTSDoor, Consock, TSCookie/PLEAD), credential theft via WinInet/CryptUnprotectData, C2 mechanisms, and an exposed open directory containing exploits (router, Citrix, Mikrotik) and tooling; it maps infrastructure, provides IOCs (hashes, IPs, domains) and outlines targeting of Taiwanese, Japanese and technology-sector entities.
