PLEAD — Malware Profile
PLEAD is a remote access tool (RAT) and downloader used by BlackTech in targeted attacks in East Asia including Taiwan, Japan, and Hong Kong. PLEAD has also been referred to as TSCookie, though more recent reporting indicates likely separation between the two. PLEAD was observed in use as early as March 2017.
MITRE ATT&CK techniques (15)
- T1001.001 Junk Data
- T1010 Application Window Discovery
- T1057 Process Discovery
- T1059.003 Windows Command Shell
- T1070.004 File Deletion
- T1071.001 Web Protocols
- T1083 File and Directory Discovery
- T1090 Proxy
- T1105 Ingress Tool Transfer
- T1106 Native API
- T1204.001 Malicious Link
- T1204.002 Malicious File
- T1555 Credentials from Password Stores
- T1555.003 Credentials from Web Browsers
- T1573.001 Symmetric Cryptography