Malware.View on attack.mitre.org
PLEAD is a remote access tool (RAT) and downloader used by BlackTech in targeted attacks in East Asia including Taiwan, Japan, and Hong Kong. PLEAD has also been referred to as TSCookie, though more recent reporting indicates likely separation between the two. PLEAD was observed in use as early as March 2017.
| Technique | Procedure example |
|---|---|
| T1001.001 Junk Data |
PLEAD samples were found to be highly obfuscated with junk code. |
| T1010 Application Window Discovery |
PLEAD has the ability to list open windows on the compromised host. |
| T1057 Process Discovery |
PLEAD has the ability to list processes on the compromised host. |
| T1059.003 Windows Command Shell |
PLEAD has the ability to execute shell commands on the compromised host. |
| T1070.004 File Deletion |
PLEAD has the ability to delete files on the compromised host. |
| T1071.001 Web Protocols |
PLEAD has used HTTP for communications with command and control (C2) servers. |
| T1083 File and Directory Discovery |
PLEAD has the ability to list drives and files on the compromised host. |
| T1090 Proxy |
PLEAD has the ability to proxy network communications. |
| T1105 Ingress Tool Transfer |
PLEAD has the ability to upload and download files to and from an infected host. |
| T1106 Native API |
PLEAD can use `ShellExecute` to execute applications. |
| T1204.001 Malicious Link |
PLEAD has been executed via malicious links in e-mails. |
| T1204.002 Malicious File |
PLEAD has been executed via malicious e-mail attachments. |
| T1555 Credentials from Password Stores |
PLEAD has the ability to steal saved passwords from Microsoft Outlook. |
| T1555.003 Credentials from Web Browsers |
PLEAD can harvest saved credentials from browsers such as Google Chrome, Microsoft Internet Explorer, and Mozilla Firefox. |
| T1573.001 Symmetric Cryptography |
PLEAD has used RC4 encryption to download modules. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.