PLEAD

S0435

Malware.View on attack.mitre.org

About this malware

PLEAD is a remote access tool (RAT) and downloader used by BlackTech in targeted attacks in East Asia including Taiwan, Japan, and Hong Kong. PLEAD has also been referred to as TSCookie, though more recent reporting indicates likely separation between the two. PLEAD was observed in use as early as March 2017.

Techniques used15

Procedure examples15

TechniqueProcedure example
T1001.001
Junk Data

PLEAD samples were found to be highly obfuscated with junk code.

T1010
Application Window Discovery

PLEAD has the ability to list open windows on the compromised host.

T1057
Process Discovery

PLEAD has the ability to list processes on the compromised host.

T1059.003
Windows Command Shell

PLEAD has the ability to execute shell commands on the compromised host.

T1070.004
File Deletion

PLEAD has the ability to delete files on the compromised host.

T1071.001
Web Protocols

PLEAD has used HTTP for communications with command and control (C2) servers.

T1083
File and Directory Discovery

PLEAD has the ability to list drives and files on the compromised host.

T1090
Proxy

PLEAD has the ability to proxy network communications.

T1105
Ingress Tool Transfer

PLEAD has the ability to upload and download files to and from an infected host.

T1106
Native API

PLEAD can use `ShellExecute` to execute applications.

T1204.001
Malicious Link

PLEAD has been executed via malicious links in e-mails.

T1204.002
Malicious File

PLEAD has been executed via malicious e-mail attachments.

T1555
Credentials from Password Stores

PLEAD has the ability to steal saved passwords from Microsoft Outlook.

T1555.003
Credentials from Web Browsers

PLEAD can harvest saved credentials from browsers such as Google Chrome, Microsoft Internet Explorer, and Mozilla Firefox.

T1573.001
Symmetric Cryptography

PLEAD has used RC4 encryption to download modules.

Groups that use it1

Campaigns0

None recorded.

References3

  1. JPCert PLEAD Downloader June 2018 Open source
    Tomonaga, S. (2018, June 8). PLEAD Downloader Used by BlackTech. Retrieved May 6, 2020.
  2. JPCert TSCookie March 2018 Open source
    Tomonaga, S. (2018, March 6). Malware “TSCookie”. Retrieved May 6, 2020.
  3. TrendMicro BlackTech June 2017 Open source
    Bermejo, L., et al. (2017, June 22). Following the Trail of BlackTech’s Cyber Espionage Campaigns. Retrieved May 5, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.