TCESB is a previously undocumented 64-bit C++ DLL malware associated with the ToddyCat cyber-espionage group. It is designed to stealthily execute payloads while circumventing protection and monitoring tools on compromised Windows systems. In observed attacks, TCESB was delivered by abusing insecure DLL loading in ESET Command-line Scanner (ecls), a vulnerability tracked as CVE-2024-11859. The malware used DLL proxying/side-loading via a malicious version.dll so that its code executed inside the trusted ecls.exe process while also redirecting exports to the legitimate Windows version.dll. Researchers observed malicious version.dll files in temp directories, and memory analysis showed both the legitimate and malicious version.dll loaded simultaneously in the ESET scanner process.
TCESB was reported as previously unseen in ToddyCat operations and appears to be derived from the open-source EDRSandBlast tool, with modifications that expanded its functionality. It can modify Windows kernel structures to disable notification routines such as process creation and image load callbacks, aiding defense evasion. To do this, it determines the running Windows kernel version and resolves kernel structure offsets either from embedded CSV data or by downloading PDB symbols for ntoskrnl.exe from the Microsoft symbol server. It also uses a Bring Your Own Vulnerable Driver technique, installing Dell's DBUtilDrv2.sys driver via an INF file through Device Manager; that driver is vulnerable to CVE-2021-36276.
After installation, TCESB polls for an extensionless payload file in the current directory; observed samples expected filenames such as kesp and ecore. The payload is decrypted with AES-128, with the key stored in the first 32 bytes of the payload file, and then executed from memory. Kaspersky detects TCESB as Trojan.Win64.ToddyCat.a and Trojan.Win64.ToddyCat.b. High-confidence detection opportunities mentioned in the source material include monitoring for installation of vulnerable drivers, unexpected kernel debug symbol downloads, and unsigned system library loads.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
This 64-bit DLL, written in C++, turned out to be a complex tool called TCESB. Previously unseen in ToddyCat attacks, it is designed to stealthily execute payloads in circumvention of protection and monitoring tools installed on the device.
This 64-bit DLL, written in C++, turned out to be a complex tool called TCESB. Previously unseen in ToddyCat attacks, it is designed to stealthily execute payloads in circumvention of protection and monitoring tools installed on the device.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This 64-bit DLL, written in C++, turned out to be a complex tool called TCESB. Previously unseen in ToddyCat attacks, it is designed to stealthily execute payloads in circumvention of protection and monitoring tools installed on the device.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
This indicates that the attackers use a DLL-proxying technique (Hijack Execution Flow, T1574) to run the malicious code... a malicious DLL exports all functions of a legitimate one... redirects calls to these functions to the original DLL... an application that loads the malicious library will continue to work as normal, with the malicious code running in the context of this application in the background.
Our analysis of the tool code found that the data in the payload file is encrypted using AES-128... The decryption key is in the first 32 bytes of the payload file, followed by the encrypted data block... The key decrypts the data block.
To modify the kernel structures that store callbacks used to notify applications of system events, TCESB deploys the Bring Your Own Vulnerable Driver (BYOVD) technique (Exploitation for Defense Evasion, T1211).
This indicates that the attackers use a DLL-proxying technique (Hijack Execution Flow, T1574) to run the malicious code... a malicious DLL exports all functions of a legitimate one... redirects calls to these functions to the original DLL... an application that loads the malicious library will continue to work as normal, with the malicious code running in the context of this application in the background.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Previously undocumented malware designed to stealthily execute payloads while circumventing protection/monitoring tools; associated with ToddyCat activity.
A tool designed to exploit vulnerabilities in security products, used to facilitate further compromise and persistence.
Malware delivered by ToddyCat APT, used to steal browser credentials, email archives, and access tokens. Delivered via exploitation of a vulnerability in ESET's security scanner.
TCESB is a previously undocumented malware delivered by ToddyCat via exploitation of a vulnerability in ESET Command Line Scanner. Its specific capabilities are not detailed in the content, but it is used as part of targeted attacks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.