• Home
    • What is
    • Computer security
      • Windows security
      • Mac security
      • Linux security
    • Mobile security
      • Android security
      • iOS Security
    • Data security
    • SCCM
    • Reviews
      • Case studies
    • Advertise
    • Contact
      • Privacy Policy
  • Subscribe now

    Loading
  • Home
  • What is
  • Computer security
    • Windows security
    • Mac security
    • Linux security
  • Mobile security
    • Android security
    • iOS Security
  • Data security
  • SCCM
  • Reviews
    • Case studies
  • Advertise
  • Contact
    • Privacy Policy
Home » Breaking Computer security Cyber Security data security Device security Latest Cybersecurity News Windows security

Flagpro malware is threatening enterprises and is backed by Chinese hackers

John Greenwood Posted On December 29, 2021
0



Flagpro malware

Japanese companies are being targeted by a novel malware called Flagpro developed by BlackTech cyber-espionage APT group.

The actors are using the Flagpro malware for network reconnaissance and start understanding the network environment and then proceed with the next stage of infiltration by downloading additional payloads.

Flagpro malware breaches enterprise networks

Like any other malware, Flagpro also starts with phishing email specifically crafted for the target environment and disguising itself is a legitimate sender. The phishing email comes with a ZIP file that is password protected and has an Excel file inside of it. This excel file has a macro code inside of it which when executed creates an exe file.

Flagpro malware

Once Flagpro is inside your network, it will first connect with the C2 server and transmits system details using the hard coded OS commands. Later, C2 server will send back further commands or a payload to enhance Flagpro malware’s modus operandi.  The communication between Flagpro and C2 server in encoded with Base64 and there are delay mechanisms that is incorporated purposely to avoid detection.

As per report from NTT Security, the Flagpro malware is being targeting Japanese firms for over an year now. The firms are from multiple verticals including defense, telecommunications, media, and more.

Flagpro malware has a newer version now

NTT researchers have also identified a newer version of Flagpro malware that is now able to erase external communication with C2 server, thus reducing the suspicion.  The newer version targeting Japan, Taiwan and English-speaking countries.

Entity behind Flagpro malware

The TrendMicro researchers identified the BlackTech APT  group in 2017  and was associated with China. In February 2021, a Unit 42 reported  BlackTech entities with WaterBear entity, which was again suspected to be a Chinese organization. BlackTech is capable of adjusting the tools to modify their attack vector and enhance Flagpro capabilities for further stealthier operation.

The NTT report have also mentioned that BlackTech is developing several malware like Flagpro, and they recently detected ‘SelfMake Loader’ and ‘Spider RAT’ malware. Security professionals need to see the patterns to detect Flagpro malware and follow the security best practices to keep their network environment safe.

Subscribe to our newsletter for daily alerts on cyber events, you can also follow us on Facebook, Linkedin, Instagram, Twitter and Reddit.

You can reach out to us via Twitter or Facebook, for any advertising requests.

Share the article with your friends


Flagpro malwareFlagpro malware attackFlagpro malware threat


Author

John Greenwood

He has been working with Cybersec and Infosec market for 12+ years now. Passionate about AI, Cybersecurity, Info security, Blockchain and Machine Learning. When he is not occupied with cybersecurity, he likes to go on bike rides!

Leave A Reply

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

  • Subscribe to our newsletter

    Loading
  • Windows security

    • Top 9 Best Log Management Tools for 2025
      September 20, 2025
    • Top 4 Remote Support Tools for 2025- Best Remote Support...
      September 18, 2025
    • Top 5 Best Unified Endpoint Management (UEM) Software...
      September 12, 2025
    • Top 5 Threat Intelligence Tools For 2025
      July 25, 2025
    • Top 5 Best Microsoft Intune Alternatives to Consider...
      July 23, 2025


  • About us

    Our vision is to deliver the trending and happening cyber events to the enthusiasts.

    We believe in delivering educational and quality content for hassle-free understanding of the subject.

  • Subscribe to our newsletter

    Loading
  • Follow us

  • Advertise with us

    You can reach us via Facebook, Linkedin, or Twitter for advertising purposes.


© The Cybersecurity Times 2022. All rights reserved.
Press enter/return to begin your search