BlackTech, Circuit Panda, Radio Panda

Description

(Trend Micro) BlackTech is a cyber espionage group operating against targets in East Asia, particularly Taiwan, and occasionally, Japan and Hong Kong. Based on the mutexes and domain names of some of their C&C servers, BlackTech’s campaigns are likely designed to steal their target’s technology.

Following their activities and evolving tactics and techniques helped us uncover the proverbial red string of fate that connected three seemingly disparate campaigns: PLEAD, Shrouded Crossbow, and of late, Waterbear.

Names

NameName-Giver
BlackTechTrend Micro
Circuit PandaCrowdStrike
Radio PandaCrowdStrike
PalmerwormSymantec
TEMP.OverboardFireEye
T-APT-03Tencent
Red DjinnPWC
Manga TaurusPalo Alto
Earth HundunTrend Micro
Canary TyphoonMicrosoft

Country

State-sponsored

Motivation

  • Information theft and espionage

First Seen

2010

Observed Sectors

Observed Countries

Tools

Operations

Information

Mitre Attack

Playbook

Other Information

Uuid

8914b19b-9d8a-469f-8b95-37db9894e070

Last Card Change

2025-06-28