The Threat Hunter Team at Symantec, a division of Broadcom (NASDAQ: AVGO), has uncovered a new espionage campaign carried out by the Palmerworm group (aka BlackTech) involving a brand new suite of custom malware, targeting organizations in Japan, Taiwan, the U.S., and China.
The attacks occurred in 2019 and continued into 2020, targeting organizations in the media, construction, engineering, electronics, and finance sectors. We observed the group using previously unseen malware in these attacks.
Palmerworm uses a combination of custom malware, dual use tools, and living-off-the-land tactics in this campaign. Palmerworm has been active since at least 2013, with the first activity seen in this campaign in August 2019.
Tactics, Tools, and Procedures
Palmerworm was observed using both dual-use tools and custom malware in these attacks.

















/cloudfront-us-east-1.images.arcpublishing.com/mco/HOPT44KA55BT7FXVWBNJ32SCNA.jpg)




/cloudfront-us-east-1.images.arcpublishing.com/mco/4VCJACT2LJGQDFIPKS3O2DMQ4M.jpg)



