PLEAD is a backdoor family used by the China-linked cyberespionage group BlackTech, also known as BRONZE CANAL and Earth Hundun. Observed since at least 2012, it is associated with information-theft campaigns targeting Taiwanese government agencies and private organizations. The family includes Windows implementations and a Linux variant known as ELF_PLEAD. PLEAD campaigns also use the separate DRIGO tool for document exfiltration.
PLEAD supports remote command execution, file upload and download, file deletion, directory and disk enumeration, process discovery, and configurable sleep intervals. It collects host and operating-system information and can steal saved credentials from Microsoft Outlook, Google Chrome, Internet Explorer, and Mozilla Firefox. Windows variants communicate over HTTP using encrypted or encoded traffic, including XOR and RC4, and can retrieve additional backdoor functionality from command-and-control servers. Some variants collect documents and transmit them through RC4-encrypted HTTP requests. Its Windows core is implemented as encrypted shellcode that a wrapper decrypts and executes in memory. Observed variants inject into Internet Explorer, including a fileless implementation, while others establish persistence through autorun entries or Windows services. Frequently modified wrappers and layered encryption help evade detection.
Delivery commonly involves spearphishing emails containing malicious attachments or links to cloud storage. Installers may masquerade as documents using right-to-left override characters and accompanying decoy documents. Exploit-bearing documents have delivered PLEAD through vulnerabilities including CVE-2015-5119, CVE-2017-11882, and CVE-2018-0802. ELF_PLEAD supports file operations, remote shells, pseudo-terminal sessions, and proxy functionality, with SSL-protected communications. An updated Linux implementation uses dynamic linking and stripped symbols to hinder analysis.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
“OLE1则包含了0day CVE-2018-0802的漏洞利用程序……这两个漏洞均位于Microsoft Office的公式编辑器Eqnedt32.exe中。” | 本次攻击使用的是一个代号为PLEAD的后门程序,该木马的核心功能以shellcode的形式存在
“OLE 2包含了CVE-2017-11882的漏洞利用程序……微软在11月份发布的补丁中,修复了CVE-2017-11882漏洞。” | 本次攻击使用的是一个代号为PLEAD的后门程序,该木马的核心功能以shellcode的形式存在
We’ve also seen PLEAD use exploits for these vulnerabilities: ... CVE-2014-6352, patched by Microsoft last October, 2014 | PLEAD’s toolset includes the self-named PLEAD backdoor and the DRIGO exfiltration tool.
We’ve also seen PLEAD use exploits for these vulnerabilities: ... CVE-2012-0158, patched by Microsoft last April, 2012 | PLEAD’s toolset includes the self-named PLEAD backdoor and the DRIGO exfiltration tool.
We’ve also seen PLEAD use exploits for these vulnerabilities: CVE-2015-5119, patched by Adobe last July, 2015 ... PLEAD also dabbled with a short-lived, fileless version of their malware when it obtained an exploit for a Flash vulnerability (CVE-2015-5119) that was leaked during the Hacking Team breach | PLEAD’s toolset includes the self-named PLEAD backdoor and the DRIGO exfiltration tool.
PLEAD also uses CVE-2017-7269, a buffer overflow vulnerability Microsoft Internet Information Services (IIS) 6.0 to compromise the victim’s server. This is another way for them to establish a new C&C or HTTP server. | PLEAD’s toolset includes the self-named PLEAD backdoor and the DRIGO exfiltration tool.
We’ve also seen PLEAD use exploits for these vulnerabilities: ... CVE-2017-0199, patched by Microsoft last April, 2017 | PLEAD’s toolset includes the self-named PLEAD backdoor and the DRIGO exfiltration tool.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
BRONZE CANAL ... Tools ... Bifrose, Deuterbear, DRIGO, Flagpro, Gh0stTimes, KIVARS, PLEAD, Spiderpig, Waterbear, XBOW
HUAPI (a.k.a BlackTech/PLEAD) was definitely the most ambitious group in Taiwan. Their attacks counts around 30% of incidents we analyzed and the targeting scope includes almost all the industries we listed. The supply chain attacks we mentioned in previous paragraphs were also conducted by them.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
PLEAD actors use a router scanner tool to scan for vulnerable routers, after which the attackers will enable the router’s VPN feature then register a machine as virtual server. This virtual server will be used either as a C&C server or an HTTP server that delivers PLEAD malware to their targets.
The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
We’ve also seen PLEAD use exploits for these vulnerabilities: CVE-2015-5119, CVE-2012-0158, CVE-2014-6352, CVE-2017-0199.
Like PLEAD, Shrouded Crossbow uses spear-phishing emails with backdoor-laden attachments that utilize the RTLO technique and accompanied by decoy documents. | PLEAD’s installers are disguised as documents using the right-to-left-override (RTLO) technique to obfuscate the malware’s filename. They are mostly accompanied by decoy documents to further trick users.
Agent Tesla can gather credentials from a number of browsers... APT33 has used a variety of publicly available tools like LaZagne to gather credentials... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge... SELECT action_url, username_value, password_value FROM logins; CryptUnprotectData
Agent Tesla can gather credentials from a number of browsers... APT3 has used tools to dump passwords from browsers... APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
The command and command numbers that differ from the prior sample are listed below: 11C SockClient >> Client/Server proxy mode 11C TravClient
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
410 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
53 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor malware/family associated in the article with the HUAPI/BlackTech intrusion set, used in broad campaigns in Taiwan including supply-chain attacks affecting multiple industries.
Listed as a tool used by the BRONZE CANAL threat profile.
Malware noted for using stolen digital signatures from Taiwan to appear legitimate and bypass trust checks.
Backdoor malware used by BlackTech for covert access to victim environments.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.