TSCookie is a malware family associated with the China-linked espionage group BlackTech, also tracked in some reporting alongside or in relation to PLEAD. It has been used in long-running intrusions targeting organizations in East Asia, particularly Taiwan and Japan, and has appeared in both Windows and Linux variants.
On Windows, TSCookie functions as a modular backdoor or loader with host reconnaissance and credential-access features. Documented capabilities include enumerating running processes, identifying the infected host’s IP address, stealing saved browser passwords from Internet Explorer, Edge, Firefox, and Chrome, and decrypting, loading, and executing DLL payloads and their resources. Its network communications have been observed protected with RC4. Public reporting also notes that the malware’s configuration handling was revised in 2019 to correct a bug affecting configuration decoding and command-and-control reconnection behavior, indicating active maintenance by its operators.
TSCookie has been delivered in BlackTech spearphishing operations via macro-enabled Excel documents, with related campaigns in 2018 and 2020 using macros to drop TSCookie. It has also been discussed in the context of broader BlackTech intrusion chains involving other implants such as PLEAD, Consock, Flagpro, Waterbear, Bifrose, and KIVARS, and overlaps have been noted with SodaMaster in some compromised environments.
A Linux variant, commonly referred to as ELF_TSCookie, shares substantial code with the Windows version but is more self-contained. Rather than relying on downloaded modules, it includes built-in functionality for arbitrary shell command execution, remote shell operation, file listing, file deletion, file movement, and file upload and download. The Linux variant uses a custom communication protocol and RC4-encrypts its payload and communications-related data. Reporting assesses that BlackTech deploys ELF_TSCookie on compromised Linux servers after intrusion, extending the family’s role beyond Windows endpoints.
Overall, TSCookie is best characterized as a BlackTech-associated espionage implant family used for post-compromise access, reconnaissance, credential theft, payload execution, and remote control across Windows and Linux environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Around May 2022, JPCERT/CC confirmed an attack activity against Japanese organizations that exploited F5 BIG-IP vulnerability (CVE-2022-1388). The targeted organizations have confirmed that data in BIG-IP has been compromised.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Our past article has presented a bug in malware “TSCookie”, which is reportedly used by BlackTech attack group. ... Just in May 2019, we confirmed that the malware had its bug fixed and was used in some attack cases.
Adversary Profile: HUAPI ... Malware: TSCOOKIE, KIVARS, CAPGELD, DBGPRINT
Uncover ELF version of PLEAD / TSCookie by JPCERT ... TSCookie and BUSYICE shared their C&C server in April 2021
25 distinct techniques documented for this family, organized by ATT&CK tactic.
Several entries refer generically to command-line interfaces, shell commands, scripting engines, or script execution without always specifying the exact interpreter.
The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
The Linux version has the following functions by default... Execute arbitrary shell command ... Table C: Commands Value Contents 0x7200AC03 Launch remote shell ... 0x7200AC04 Send a command to remote shell ... 0x7200AC10 Execute command
Specifically, upon gaining an initial foothold into a target network and gaining administrator access to network edge devices, BlackTech cyber actors often modify the firmware to hide their activity across the edge devices to further maintain persistence in the network.
The payload itself is RC4-encrypted in both versions... Up to offset 0x1C, the contents are encrypted with the RC4 key and random data in the configuration.
Specifically, upon gaining an initial foothold into a target network and gaining administrator access to network edge devices, BlackTech cyber actors often modify the firmware to hide their activity across the edge devices to further maintain persistence in the network.
Agent Tesla can gather credentials from a number of browsers... APT33 has used a variety of publicly available tools like LaZagne to gather credentials... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge... SELECT action_url, username_value, password_value FROM logins; CryptUnprotectData
Agent Tesla can gather credentials from a number of browsers... APT3 has used tools to dump passwords from browsers... APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge
Specifically, upon gaining an initial foothold into a target network and gaining administrator access to network edge devices, BlackTech cyber actors often modify the firmware to hide their activity across the edge devices to further maintain persistence in the network.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
For encryption, RC4 is still used, but the key is generated differently.
This update has also fixed the issue where the malware fails to reconnect to a C&C server for a few days.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
74 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
46 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor malware capable of injecting code into multiple Windows and browser processes.
Malware used by BlackTech and found on the attacker-controlled server alongside the BIG-IP exploit code.
Identifies the IP address of infected hosts.
Backdoor that identifies the IP address of infected hosts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.