Flagpro, also known as BUSYICE, is a Windows downloader with backdoor functionality used by the China-linked cyberespionage group BlackTech, also tracked as BRONZE CANAL, Earth Hundun, and Red Djinn. It serves as an early-stage implant for profiling compromised environments and downloading and executing additional malware, including BTSDoor. Confirmed targeting includes Japanese organizations in the defense, media, and telecommunications sectors.
Flagpro is typically delivered through tailored spearphishing emails impersonating legitimate business communications. Attachments include malicious macro-enabled Excel documents, often enclosed in password-protected ZIP or RAR archives. Enabling the macros deploys the executable and establishes persistence through Windows startup-folder execution. Flagpro supports operating-system command execution and has been used to discover the current user, network configuration, remote systems, and network shares. It can retrieve and decrypt saved Microsoft WinInet credentials from the Windows Credential Store and exfiltrate credentials and command results.
Command-and-control communication uses HTTP through Internet Explorer COM objects and the IWebBrowser2 interface, with Base64-encoded commands and returned data. Flagpro periodically polls for instructions and can download and execute second-stage payloads. It recognizes localized Windows Security dialogs associated with Japanese, Taiwanese, and English-language environments and suppresses security or Internet Explorer dialogs to conceal external communications. An MFC-based variant identified as version 2.0 adds enhanced dialog handling and code obfuscation.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
BRONZE CANAL ... Tools ... Bifrose, Deuterbear, DRIGO, Flagpro, Gh0stTimes, KIVARS, PLEAD, Spiderpig, Waterbear, XBOW
2021: dropping FlagPro ... The downloader can perform C2 via the IWebBrowser2 interface and execute basic commands ... Flagpro can download and execute a backdoor.
BUSYICE (aka Flagpro) • BUSYICE is HTTP client written in C/C++, which works as both backdoor/downloader
24 distinct techniques documented for this family, organized by ATT&CK tactic.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, enumerating PIDs, checking for specific process names, or using APIs such as CreateToolhelp32Snapshot and commands such as tasklist and ps.
19 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
48 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as a tool used by the BRONZE CANAL threat profile.
Custom malware family cited as part of BlackTech’s toolkit for stealthy access and persistence.
Executes malicious VBA macros embedded in .xlsm files.
Backdoor malware used to execute net view to discover mapped network shares.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.