Cyber Threat Report: 'People's Republic of China-Linked Cyber Actors Hide in Router Firmware'

Report Author CISA
Publication Date 2023-09-27
Original Reporting Source
Attributed to Nation China
Related Intrusion Sets BlackTech
Victim Sectors National Government, Telecommunications, Defense, Technology

This Cybersecurity Advisory from CISA and partners details activities of the People's Republic of China (PRC)-linked cyber actors known as BlackTech. According to the advisory, BlackTech has targeted multiple sectors including government, industrial, technology, media, electronics, and telecommunication in the U.S. and Japan. The group uses custom malware, dual-use tools, and 'living off the land' tactics to modify router firmware and exploit domain-trust relationships for pivoting within networks. The advisory outlines TTPs and IoCs and provides recommended mitigations to detect and protect organizations against the threat from BlackTech actors.

Cyber Threat Graph Context

Explore how this report relates to the wider threat graph

Mitigations to defend against the techniques in this report

Identified MITRE ATT&CK Techniques