ESET attributed a 2021–2022 cyberespionage campaign to the Tick APT group after attackers breached an East Asian developer of data-loss prevention software and compromised its internal update servers. The intrusion allowed the group to execute malware inside the vendor’s network, where it deployed several tools including the previously undocumented ShadowPy downloader, the Netboy backdoor, Ghostdown, and customized ReVBShell payloads.
Investigators said the update-server compromise was likely used primarily for lateral movement within the DLP company rather than mass distribution to outside targets, but trojanized legitimate Q-Dir installers were also used and later reached systems at two customers in East Asia through remote support activity. Because the vendor served government and military organizations, the operation appears to have been aimed at intelligence collection rather than disruptive attacks, extending Tick’s access from the software provider into downstream customer environments.

TTPs, infrastructure, and targeting history in one profile.
7 events from the most recent confirmed update back to the earliest known activity.
ESET disclosed a 2021–2022 campaign targeting an East Asian DLP software developer and attributed it with high confidence to the Tick APT group. The report also documented malware used in the intrusion, including the previously undocumented ShadowPy downloader, Netboy, Ghostdown, and customized ReVBShell payloads.
In June 2022, attackers again transferred trojanized Q-Dir installers to customer systems via remote support tooling. The activity formed part of the same intrusion chain affecting two customers of the DLP vendor.
In February 2022 and again in June 2022, trojanized Q-Dir installers were transferred to systems at two East Asian customers in the engineering and manufacturing sectors using the remote support tools helpU and ANYSUPPORT. This resulted in malware execution on customer systems.
In September 2021, another malicious ZIP update package was downloaded from a public-facing server and deployed inside the DLP company's network via the legitimate update agent. ESET assessed the compromised update infrastructure was likely used for lateral movement within the vendor rather than broad external distribution.
In June 2021, a malicious ZIP update package was downloaded from an internal server and deployed by the vendor's legitimate update agent on machines inside the DLP company's network. The executable contacted 103.127.124[.]117 to retrieve a key used to decrypt an embedded payload assessed as ReVBShell.
Starting in April 2021, the attackers placed both 32-bit and 64-bit trojanized installers for the legitimate Q-Dir application inside the DLP vendor's network. These installers were later used to deploy payloads including customized ReVBShell variants.
Attackers gained access to the network of an East Asian company that develops data-loss prevention software. ESET later assessed the operation as a cyberespionage campaign attributed with high confidence to the Tick APT group.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 23 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.