TESDAT is a Windows loader used by the Earth Kurma cyberespionage group against government and telecommunications organizations in Southeast Asia. It establishes persistence by loading follow-on payloads, including Cobalt Strike beacons and rootkits, directly into memory. TESDAT uses the SwitchToFiber API to inject shellcode into memory. It also collects common office-document formats, stages and password-protects them in WinRAR archives, and supports their exfiltration through cloud-storage services including Dropbox and OneDrive. Earth Kurma used Active Directory distributed-file replication to make staged archives accessible across domain controllers before exfiltration.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Loaders like DUNLOADER, TESDAT, and DMLOADER achieved persistence by loading next stage payloads into memory. TESDAT collected documents, staged them, and archived them with WinRAR.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
“TESDAT collecting documents with the extension .pdf, .doc, .docx, .xls, .xlsx, .ppt, .pptx.”
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom loader used for persistence and deployment of additional payloads, including Cobalt Strike and rootkits.
Custom loader used for in-memory execution of payloads and supporting data exfiltration via cloud services (e.g., Dropbox/OneDrive). Also used to deliver Cobalt Strike beacons.
Custom tool used in the campaign both to establish persistence/load next-stage payloads in-memory and to stage documents for exfiltration (collects specific document types, stages them in a tmp folder, and archives them with WinRAR using a password).
TESDAT is a loader used by Earth Kurma to load and execute payloads, using techniques such as SwitchToFiber API to evade detection. It is used to deploy further malware and exfiltrate data.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.