Most of the Win32 assessment s/w I used in the good/bad old days of NT (take your pick) was straight-up blackhat tools - because that's what was availble. Blackhats are also responsible for a lot of proof of concept work that results in changes in core protocols - if not new protocols. I think you should reframe the journalist's question to reflect this kind of symbiosis.