This top Microsoft Office alternative has been hijacked by Chinese hackers — and their malware is coming for your devices
Chinese hackers are hijacking legitimate software updates to deliver backdoors capable of stealing sensitive information from the target endpoints, experts have warned.
A new report from cybersecurity researchers ESET recently observed a previously unknown threat actor which they dubbed Blackwood.
This group, which apparently is on the Chinese government’s payroll, delivers malware through software updates for legitimate tools such as WPS Office, Tencent QQ, and Sogou Pinyin.
This doesn’t seem to be a classic supply chain attack, as the software itself is not compromised, and neither are the updates. Instead, the hackers intercept the traffic between the server hosting the update and the target endpoint and work in the middle. It is unknown exactly how the attackers are able to intercept the traffic. ESET believes Blackwood might be using an implant in the victims’ networks, possibly in routers and similar devices.
The malware they look to install on target endpoints is called NSPX30. The researchers describe this malware as “sophisticated”, and say its built upon a simple backdoor from 2005 called Project Wood.
NSPX30 has grown into a capable tool, however. Today, it can log keystrokes, grab screenshots, pull system information, and exfiltrate other data from the devices. It can also steal chat logs and contact lists from different communications apps, including Telegram, and Skype. Finally, it can terminate processes by PID, create a reverse shell, move files, and uninstall itself if necessary.
Most of the victims seem to be located in China. However, there are compromised devices in Japan, and the United Kingdom, too. Blackwood’s activities can be traced back to 2020.
Those looking to stay protected from Blackwood and similar threats should read ESET’s in-depth report on the malware and its operations, here. This report, among other things, offers a list of indicators of compromise which IT teams can use to protect their infrastructure.
More from TechRadar Pro
Chinese hackers are hijacking legitimate software updates to deliver backdoors capable of stealing sensitive information from the target endpoints, experts have warned. A new report from cybersecurity researchers ESET recently observed a previously unknown threat actor which they dubbed Blackwood. This group, which apparently is on the Chinese government’s payroll,…
Recent Posts
- LG Promo Codes and Coupons for June 2026
- 30% Off Canon Promo Codes | June 2026
- Steam Machine and Steam Frame are coming ‘this summer’
- Valve says it’s ready to launch the Steam Machine this summer
- Best Buy slashes up to $400 off Apple tech in a limited-time sale — get AirPods, MacBooks, iPads and Apple Watches from $99.99
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023