TSCookie

S0436

Malware.View on attack.mitre.org

About this malware

TSCookie is a remote access tool (RAT) that has been used by BlackTech in campaigns against Japanese targets.. TSCookie has been referred to as PLEAD though more recent reporting indicates a separation between the two.

Techniques used13

Procedure examples13

TechniqueProcedure example
T1016
System Network Configuration Discovery

TSCookie has the ability to identify the IP of the infected host.

T1055
Process Injection

TSCookie has the ability to inject code into the svchost.exe, iexplorer.exe, explorer.exe, and default browser processes.

T1057
Process Discovery

TSCookie has the ability to list processes on the infected host.

T1059.003
Windows Command Shell

TSCookie has the ability to execute shell commands on the infected host.

T1071.001
Web Protocols

TSCookie can multiple protocols including HTTP and HTTPS in communication with command and control (C2) servers.

T1083
File and Directory Discovery

TSCookie has the ability to discover drive information on the infected host.

T1090
Proxy

TSCookie has the ability to proxy communications with command and control (C2) servers.

T1095
Non-Application Layer Protocol

TSCookie can use ICMP to receive information on the destination server.

T1105
Ingress Tool Transfer

TSCookie has the ability to upload and download files to and from the infected host.

T1140
Deobfuscate/Decode Files or Information

TSCookie has the ability to decrypt, load, and execute a DLL and its resources.

T1204.001
Malicious Link

TSCookie has been executed via malicious links embedded in e-mails spoofing the Ministries of Education, Culture, Sports, Science and Technology of Japan.

T1555.003
Credentials from Web Browsers

TSCookie has the ability to steal saved passwords from the Internet Explorer, Edge, Firefox, and Chrome browsers.

T1573.001
Symmetric Cryptography

TSCookie has encrypted network communications with RC4.

Groups that use it1

Campaigns0

None recorded.

References3

  1. JPCert BlackTech Malware September 2019 Open source
    Tomonaga, S.. (2019, September 18). Malware Used by BlackTech after Network Intrusion. Retrieved May 6, 2020.
  2. JPCert PLEAD Downloader June 2018 Open source
    Tomonaga, S. (2018, June 8). PLEAD Downloader Used by BlackTech. Retrieved May 6, 2020.
  3. JPCert TSCookie March 2018 Open source
    Tomonaga, S. (2018, March 6). Malware “TSCookie”. Retrieved May 6, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.