PLEAD is a long-running cyber espionage campaign active since at least 2012 and closely associated with BlackTech, an East Asia-focused intrusion set. It is primarily known for targeting Taiwanese government agencies and private-sector organizations to steal sensitive documents and other confidential information. Reporting has linked PLEAD with other BlackTech-associated activity clusters, including Shrouded Crossbow and Waterbear, based on shared infrastructure, overlapping victimology, similar delivery methods, and coordinated presence on the same victim networks. PLEAD commonly relies on spear-phishing for initial access, using document-themed lures, malicious attachments, and links to cloud-hosted payloads. A hallmark tradecraft element is use of the right-to-left override technique to disguise executables as benign document files. The campaign has also exploited multiple client- and server-side vulnerabilities, including CVE-2012-0158, CVE-2014-6352, CVE-2015-5119, CVE-2017-0199, and CVE-2017-7269. Operators have additionally used compromised network devices and vulnerable servers to support command-and-control and malware delivery. The PLEAD backdoor supports broad post-compromise functionality, including system reconnaissance, remote shell access, file upload, execution of additional programs, file deletion, and harvesting of saved credentials from browsers and Outlook. The campaign has also used the DRIGO tool to search infected systems for documents and exfiltrate stolen files. Its operational objective has centered on theft of sensitive materials, including government, defense, budgetary, foreign affairs, contract, internal affairs, public security, and password-related documents. PLEAD is best characterized as an espionage-focused intrusion campaign rather than a ransomware or extortion actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Information theft campaign targeting confidential documents, especially against Taiwanese government and private-sector entities.
Targeted attack campaign known for using RTLO filename spoofing and for attacks against Taiwan ministries exploiting CVE-2012-0158.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.