Newly Discovered China-Linked Hacker Group, Blackwood, Plants Sophisticated Spyware in Legitimate Software Updates

In the ever-evolving landscape of cyber threats, a new China-linked hacker group, dubbed Blackwood, has recently emerged. This sophisticated group has been quietly infiltrating systems by planting spyware in legitimate software updates since 2018. In this article, we will delve into the details of their malware, known as NSPX30, its targets, and the activities of the Blackwood APT group.

Description of the malware

The malware employed by Blackwood, named NSPX30, is a highly advanced tool deployed through mechanisms native to popular software platforms such as WPS Office, Sogou Pinyin, and Tencent QQ. Through these unsuspecting channels, the spyware skillfully targets engineering and manufacturing businesses, as well as individuals located in the UK, Japan, and China.

Background on the Blackwood APT Group

Blackwood aligns itself with China and has been actively operating since at least 2018. Their primary focus is cyber espionage, with Chinese and Japanese individuals and companies being their primary targets. Their extensive hacking campaigns have created concerns within the global cybersecurity community.

Infection Mechanism

One of the key aspects of Blackwood’s strategy is compromising machines when legitimate software attempts to download updates from trusted servers. This method allows them to slip their spyware into unsuspecting systems, targeting both personal and corporate devices. The recent surge of malicious activity in China prompted the discovery of the NSPX30 malware.

Components of NSPX30 Spyware

NSPX30 is a complex, multistage implant, involving various components that work synergistically to infiltrate and gather sensitive information. The malware consists of a dropper, an installer, loaders, an orchestrator, and a potent backdoor that grants Blackwood persistent access to compromised systems.

Victims of the spyware

Multiple victims have fallen prey to the NSPX30 spyware. This includes individuals residing in China and Japan, a Chinese-speaking individual connected to a prominent UK public research university, a large manufacturing and trading company within China, and the office of a Japanese corporation located in China. Blackwood’s extensive reach and targeting demonstrate the group’s determination and range.

Persistent and Goal-Oriented Attacks

One characteristic of Blackwood’s attacks is their persistence. If the hackers lose access to a system, they relentlessly attempt to reconnect, highlighting their targeted and goal-oriented campaigns. This dedication suggests that Blackwood is not an opportunistic group but rather one focused on achieving specific objectives.

Uncertainty Surrounding Delivery Method

Despite extensive research into Blackwood’s activities, the precise method employed to deliver malicious updates containing NSPX30 spyware remains unknown. Experts continue to investigate this critical aspect, seeking to unveil the intricacies of their distribution mechanism.

The discovery of the Blackwood hacker group and their sophisticated NSPX30 spyware underscores the evolving nature of cyber threats originating from China. Their ability to infiltrate systems through legitimate software updates poses a significant risk, particularly for engineering and manufacturing businesses across the UK, Japan, and China. Cybersecurity professionals and organizations must remain vigilant, implementing robust security measures to fend off such targeted attacks. Ongoing investigations and cooperation within the cybersecurity community are crucial in exposing and neutralizing the threat posed by groups like Blackwood.

Explore more

How AI Agents Work: Types, Uses, Vendors, and Future

From Scripted Bots to Autonomous Coworkers: Why AI Agents Matter Now Everyday workflows are quietly shifting from predictable point-and-click forms into fluid conversations with software that listens, reasons, and takes action across tools without being micromanaged at every step. The momentum behind this change did not arise overnight; organizations spent years automating tasks inside rigid templates only to find that

AI Coding Agents – Review

A Surge Meets Old Lessons Executives promised dazzling efficiency and cost savings by letting AI write most of the code while humans merely supervise, but the past months told a sharper story about speed without discipline turning routine mistakes into outages, leaks, and public postmortems that no board wants to read. Enthusiasm did not vanish; it matured. The technology accelerated

Open Loop Transit Payments – Review

A Fare Without Friction Millions of riders today expect to tap a bank card or phone at a gate, glide through in under half a second, and trust that the system will sort out the best fare later without standing in line for a special card. That expectation sits at the heart of Mastercard’s enhanced open-loop transit solution, which replaces

OVHcloud Unveils 3-AZ Berlin Region for Sovereign EU Cloud

A Launch That Raised The Stakes Under the TV tower’s gaze, a new cloud region stitched across Berlin quietly went live with three availability zones spaced by dozens of kilometers, each with its own power, cooling, and networking, and it recalibrated how European institutions plan for resilience and control. The design read like a utility blueprint rather than a tech

Can the Energy Transition Keep Pace With the AI Boom?

Introduction Power bills are rising even as cleaner energy gains ground because AI’s electricity hunger is rewriting the grid’s playbook and compressing timelines once thought generous. The collision of surging digital demand, sharpened corporate strategy, and evolving policy has turned the energy transition from a marathon into a series of sprints. Data centers, crypto mines, and electrifying freight now press