T9000 is a Windows espionage malware family with remote surveillance and collection capabilities. It has been observed gathering host profiling data during installation, including the logged-in username, usernames associated with running processes to determine whether it is executing as SYSTEM, network identifiers such as MAC and IP addresses, and local system time. It also performs security software discovery to identify antivirus and related defensive products.
The malware supports screen capture, including screenshots of the full desktop and targeted application windows, storing the captured data in encrypted form prior to operator retrieval or exfiltration. It also includes audio and video surveillance functionality through abuse of the Skype API, enabling recording of Skype calls and storage of the resulting data in encrypted form. In addition, T9000 enumerates connected drives to identify removable media and searches removable storage for files matching predefined document-oriented extensions, then copies collected content in encrypted form to a local user directory.
A notable execution characteristic is its use of DLL side-loading for stealth and execution, leveraging a legitimate Microsoft executable with a side-loading weakness to load part of the malware. Overall, T9000 is best characterized as a surveillance-oriented remote access trojan used for post-compromise reconnaissance and collection on Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all, netsh.exe, ifconfig, arp, route, nbtstat, and related APIs/commands to gather IP, MAC, DNS, DHCP, gateway, proxy, routing, ARP, and adapter information.
The content repeatedly describes malware and threat actors collecting the username, identifying the current user, enumerating logged-on users, or running commands such as whoami, query user, and quser to determine user context on compromised systems.
Several entries describe identifying whether the current user has admin privileges, determining privilege level, identifying groups the user belongs to, or verifying execution as SYSTEM.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, BIOS, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, and WMI to gather host information.
ADVSTORESHELL can list connected devices. APT28 uses a module to receive a notification every time a USB mass storage device is inserted into a victim. APT37 has a Bluetooth device harvester, which uses Windows Bluetooth APIs to find information on connected Bluetooth devices.
The content repeatedly describes malware and threat actors collecting the current date, time, or time zone from victim systems, including examples such as "The net time command can be used... to determine the local or remote system time" and commands like "net time \\hostname" and "w32tm /tz".
AppleSeed has automatically collected data from USB drives... Crutch can automatically monitor removable drives in a loop and copy interesting files... T9000 searches removable storage devices for files with a pre-defined list of file extensions.
The content is a MITRE ATT&CK-style listing of malware and threat actors that "can capture screenshots," "take screenshots," "perform screen captures," or "watch the victim's screen." It ends with references to "CopyFromScreen" and "xwd."
Agrius used a custom tool, sql.net4.exe, to query SQL databases and then identify and extract personally identifiable information... AppleSeed has automatically collected data from USB drives, keystrokes, and screen images before exfiltration... Ember Bear engages in mass collection from compromised systems during intrusions.
30 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor that gathers and beacons the logged-in account username during installation and checks if it runs as SYSTEM.
Gathers and beacons MAC and IP addresses during installation.
Remote access trojan that gathers and transmits system time during installation.
Gathers and beacons the logged-in username during installation and checks process usernames to determine SYSTEM privileges.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.