Waterbear is a modular Windows backdoor associated with the China-linked espionage group BlackTech, also tracked as BRONZE CANAL, Earth Hundun, Palmerworm, Circuit Panda, and Shrouded Crossbow. It has been used in long-running cyber espionage operations primarily targeting organizations in East Asia, with repeated reporting on intrusions against Taiwanese government entities and broader targeting linked to government, technology, telecommunications, and related sectors.
Waterbear is characterized by a staged architecture in which a loader component retrieves or decrypts a main backdoor and loads it directly into memory. Reported variants have used patched legitimate server applications as loader components, and some campaigns employed DLL side-loading or DLL hijacking to launch the malware with elevated privileges. The malware has also been observed using shellcode injection into Windows services, in-memory execution, and API-based execution mechanisms. Its loader has been described as decrypting RC4-protected payloads before execution.
The malware includes discovery and evasion functionality. Reported behaviors include identifying specific security products or processes, querying the Windows Registry to assess the environment, and checking for the presence of defensive software before proceeding. Waterbear has also been noted for anti-analysis and defense-evasion measures such as Heaven’s Gate-style mixed 32-bit and 64-bit execution, junk-byte padding around decoded shellcode, self-modifying code, and inflated binaries intended to complicate static analysis and file-based detection.
Operational reporting links Waterbear to post-compromise activity and sustained access rather than broad opportunistic distribution. It is assessed to function as a secondary payload used after initial access has already been established, helping operators maintain persistence and continue follow-on operations inside victim environments. Multiple reports connect Waterbear with BlackTech campaigns that emphasized stealth, long-term access, and document theft from high-value targets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
BRONZE CANAL ... Tools ... Bifrose, Deuterbear, DRIGO, Flagpro, Gh0stTimes, KIVARS, PLEAD, Spiderpig, Waterbear, XBOW
Waterbear similarly employs a modular approach to its malware. A loader component executable will connect to the C&C server to download the main backdoor and load it in memory.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
The content is a MITRE ATT&CK-style listing of many malware families and threat groups using Windows/native OS APIs for execution, injection, discovery, anti-debugging, and other actions, ending with 'NtCreateProcess' and 'fork()'.
Waterbear similarly employs a modular approach to its malware. A loader component executable will connect to the C&C server to download the main backdoor and load it in memory.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
Specifically, upon gaining an initial foothold into a target network and gaining administrator access to network edge devices, BlackTech cyber actors often modify the firmware to hide their activity across the edge devices to further maintain persistence in the network.
Last year, Waterbear captured interest in the cybersecurity industry after implementing API hooking to hide its activities by abusing security products.
To scupper analysis attempts, the Waterbear loader will also use RC4 encryption on its main payload... The size of the malware's binary was also inflated in an attempt to bypass file-based scanners.
Examples throughout the content include 'encrypted payloads decrypted and executed in memory,' 'encrypts its configuration file,' 'AES-encrypted resource,' 'RC4 encrypted embedded scripts,' and 'payload includes an encrypted main component.'
Self Modifying Code - Waterbear... Before self-modifying After self-modifying Only the wait-for-connection function is left
Using beginthreadex() acts as a proxy and starts the new thread at threadstartex(), instead of using the address where the shellcode is located as if using CreateThread() directly | Recent Injection Technique used by APT
Bisonal has deleted Registry keys to clean up its prior activity. FIN8 has deleted Registry keys during post compromise cleanup activities. SUNBURST also deleted previously-created Image File Execution Options (IFEO) Debugger registry values and registry keys related to HTTP proxy to clean up traces of its activity.
The content is a long ATT&CK-style listing of malware and threat groups that 'decrypt', 'decode', 'deobfuscate', 'unpack', or 'decompress' payloads, strings, configuration data, shellcode, and files prior to execution or use.
Known as 'Heaven's Gate,' the misdirection technique is used to trick Microsoft Windows operating systems into executing 64-bit code, even when declared as a 32-bit process. This, in turn, can be used to bypass security engines... some monitor/analysis systems will only apply 32-bit analysis and will fail the 64-bit part.
Waterbear 'can hook the ZwOpenProcess and GetExtendedTcpTable APIs called by the process of a security product to hide PIDs and TCP records from detection.'
Last year, Waterbear captured interest in the cybersecurity industry after implementing API hooking to hide its activities by abusing security products.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
Specifically, upon gaining an initial foothold into a target network and gaining administrator access to network edge devices, BlackTech cyber actors often modify the firmware to hide their activity across the edge devices to further maintain persistence in the network.
Specifically, upon gaining an initial foothold into a target network and gaining administrator access to network edge devices, BlackTech cyber actors often modify the firmware to hide their activity across the edge devices to further maintain persistence in the network.
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
Known as 'Heaven's Gate,' the misdirection technique is used to trick Microsoft Windows operating systems into executing 64-bit code, even when declared as a 32-bit process. This, in turn, can be used to bypass security engines... some monitor/analysis systems will only apply 32-bit analysis and will fail the 64-bit part.
The content repeatedly describes threat actors and malware disabling or modifying security tools, EDR/AV, logging, firewall rules, integrity checkers, and security settings; e.g., 'Agrius used several mechanisms to try to disable security tools' and 'BlackByte disabled security tools such as Windows Defender and the Raccine anti-ransomware tool during operations.'
91 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
36 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as a tool used by the BRONZE CANAL threat profile.
A complex backdoor/RAT ecosystem used by Earth Hundun/BlackTech, featuring loader+downloader stages, custom (salted) RC4 and/or CryptUnprotectData-based decryption flows, extensive anti-analysis (anti-debug/anti-sandbox/AV evasion, binary padding, anti-memory scanning), and a custom C2 protocol to retrieve a next-stage RAT with broad remote administration and file/process/service/registry capabilities.
BlackTech-linked custom malware used to maintain covert access and persistence in targeted networks.
Backdoor malware that injects decrypted shellcode into the LanmanServer service.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.