TrillClient is a custom information-stealing malware associated with the China-linked espionage cluster tracked as Earth Estries, with reporting also noting overlaps with activity associated with Salt Typhoon. It is designed primarily to harvest browser-resident credential material and related authentication data from Windows systems, especially Chromium-based browser profile stores and Windows credential-protection data. Observed collection includes browser login databases, cookie stores, browser state data, and Microsoft Protect material, indicating a focus on credential theft and potential session abuse in support of follow-on intrusion activity.
The malware has been described as a heavily obfuscated Go-based toolset. It stages stolen data in temporary directories, archives the collected material, encrypts it with an XOR-based routine, and exfiltrates the result over SMTP to actor-controlled mail infrastructure. TrillClient also retrieves tasking from a GitHub-hosted configuration source and can update itself when a newer version is available, showing simple command-and-control and maintenance functionality through public web services.
Operationally, TrillClient appears in broader post-compromise attack chains alongside tools such as HemiGate, SparrowDoor, CrowDoor, Cobalt Strike, and other Earth Estries malware. It has been used after initial access obtained through exploitation of internet-facing enterprise systems and during lateral movement phases in long-dwell espionage intrusions. Delivery has been observed via CAB-packaged components extracted on victim hosts, and the malware can install itself as a Windows service for persistence. Victimology associated with the surrounding campaigns includes telecommunications providers, government entities, technology organizations, and related service providers across multiple regions. TrillClient’s role within these operations is credential collection from browser caches and protected stores to support sustained access, account compromise, and intelligence gathering.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"Earth Estries will collect user credentials... employs the TrillClient information stealer... primarily collecting user credentials from browser user profiles."
14 distinct techniques documented for this family, organized by ATT&CK tactic.
“Zingdoor is packed using UPX and heavily obfuscated…” / “TrillClient… heavily obfuscated… for anti-analysis.”
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only in relation to linked attack chains and overlapping infrastructure.
Credential-harvesting tool used to extract credentials (notably from browser caches/storage) to enable use of valid accounts and privilege escalation.
Credential stealer that uses a PowerShell script to collect browser profile data (Chrome 'Login Data', 'Cookies', 'Local State') and Microsoft Protect data, stages it in a temp directory, archives it with tar, XOR-encrypts it, and exfiltrates via SMTP to a Gmail account.
Custom Go-based browser credential/cookie stealer delivered in a CAB and extracted via expand.exe; pulls per-victim commands and versioning from a hard-coded GitHub config; stages data in temp, archives, XOR-encrypts, and exfiltrates via SMTP to an actor-controlled Gmail account; supports self-update.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.