Treadstone is the internal name of a malware controller/control panel referenced in leaked 2024 i-Soon (Anxun Information Technology) documents and previously mentioned in U.S. government reporting on Chinese intrusion activity. The leaked materials include a screenshot of a Linux remote-control management system whose malware control panel is named “Treadstone.” Reporting cited in the content notes that this controller name was also referenced in a U.S. indictment of Chengdu 404 employees and associated with APT41/Elemental Taurus, and another analysis describes it as the controller for Winnti. The surrounding i-Soon documentation indicates the broader remote-control tooling ecosystem supported Windows, macOS, iOS, Android, and Linux implants, with capabilities across the product line including command execution, file and service management, screen capture, keylogging, pivoting through infected hosts, and mobile collection such as device identifiers, location, microphone activation, contacts, files, and in some cases SMS/IM access and persistence. The leak further suggests i-Soon may have marketed or supported this controller software and that tool sharing or resale may have occurred across Chinese-affiliated intrusion sets, complicating attribution. Infrastructure overlaps in the same leaked corpus include 118.31.3[.]116:44444 shown in an admin panel and separately reported as ShadowPad C2 infrastructure attributed to the Winnti group. High-confidence attribution should be limited to Treadstone being a malware controller name appearing in i-Soon Linux malware management materials and in prior reporting tied to Chengdu 404/APT41 and Winnti-related activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“the internal name of this tool (“TreadStone”) … mentioned in the FBI indictment … as the controller for Winnti.”
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Linux implant/controller referenced in leaked I-Soon tooling; notable for external linkage to a Winnti controller name in a U.S. FBI indictment (Chengdu 404 context). The leak describes Linux implant capabilities including SOCKS5 proxying and TCP port reuse.
A malware controller/control-panel software marketed by i-Soon, described as designed to work with Winnti malware and used to manage remote control capabilities (at least for Linux, per the leaked manual screenshot).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.