CookiETagRAT is a C++ remote-access trojan used in the SilkParasite cyberespionage operation. It receives and executes operator commands concealed in HTTP Cookie and ETag response headers, using per-host ChaCha20-derived cryptographic material. It has been deployed in intrusions against government organizations in Central Asia. SilkParasite is assessed with medium confidence to be China-nexus activity, although it has not been conclusively attributed to a single named threat actor. CookiETagRAT was one of five previously undocumented RAT families identified in this operation and was deployed through DLL sideloading involving a legitimate signed Windows application.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
CookiETagRAT IOCs include tak_deco_lib.dll, easyhook64.dll, and a filesystem XOR key.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
CookiETagRAT (C++), which uses HTTP Cookie / ETag response headers as C2 to receive and execute commands.
Rather than using one noisy implant, the actors maintained several tools, changed their supporting files between builds, and used cloud services and normal-looking traffic to make investigation harder. | CookiETagRAT concealed commands in HTTP Cookie and ETag headers
CookiETagRAT hides its tasking in the headers instead. Commands arrive inside HTTP Cookie and ETag response headers, with results returned in the body.
It runs its command channel over trusted services like Google Drive, hides inside legitimately signed applications, and keeps its footprint deliberately small.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A newly named remote-access trojan family used in the SilkParasite cyberespionage campaign against Central Asian government bodies.
Remote access trojan that hides command data in HTTP Cookie and ETag headers to blend malicious traffic with normal web communications.
A previously undocumented remote access Trojan used by SilkParasite in a spear-phishing campaign against Central Asian government organizations to establish and maintain long-term access.
A previously undocumented remote access trojan used in the SilkParasite cyberespionage operation targeting government bodies across Central Asia.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.