TSCookie is a malware family used by the BlackTech threat group, also known as HUAPI, with variants targeting Windows and Linux. It combines payload-loading functionality with credential theft, host reconnaissance, and remote-control capabilities. BlackTech has distributed Windows variants through malicious Excel documents containing VBA macros, including campaigns observed in 2018 and 2020.
On Windows, TSCookie can decrypt, load, and execute DLL payloads and their resources, inject code into Windows service-host, desktop-shell, and browser processes, enumerate running processes, and identify the infected host's IP address. It can steal passwords saved in Internet Explorer, Microsoft Edge, Firefox, and Chrome. Windows variants support HTTP, HTTPS, and a custom communication protocol, encrypt network communications with RC4, and can use ICMP to receive destination-server information.
The Linux variant, known as ELF_TSCookie, shares substantial code with the Windows version but uses a smaller configuration and supports only a custom communication protocol. It incorporates built-in functionality rather than relying on downloaded modules, allowing operators to execute arbitrary shell commands, launch a remote shell, list and manipulate files, and upload or download files. Both platform variants use RC4 to encrypt payloads. A May 2019 update corrected a Windows configuration-decoding bug and an associated problem that prevented reliable reconnection to command-and-control infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Around May 2022, JPCERT/CC confirmed an attack activity against Japanese organizations that exploited F5 BIG-IP vulnerability (CVE-2022-1388). The targeted organizations have confirmed that data in BIG-IP has been compromised.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Our past article has presented a bug in malware “TSCookie”, which is reportedly used by BlackTech attack group. ... Just in May 2019, we confirmed that the malware had its bug fixed and was used in some attack cases.
Adversary Profile: HUAPI ... Malware: TSCOOKIE, KIVARS, CAPGELD, DBGPRINT
Uncover ELF version of PLEAD / TSCookie by JPCERT ... TSCookie and BUSYICE shared their C&C server in April 2021
24 distinct techniques documented for this family, organized by ATT&CK tactic.
Several entries refer generically to command-line interfaces, shell commands, scripting engines, or script execution without always specifying the exact interpreter.
The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
The Linux version has the following functions by default... Execute arbitrary shell command ... Table C: Commands Value Contents 0x7200AC03 Launch remote shell ... 0x7200AC04 Send a command to remote shell ... 0x7200AC10 Execute command
Agent Tesla can gather credentials from a number of browsers... APT33 has used a variety of publicly available tools like LaZagne to gather credentials... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge... SELECT action_url, username_value, password_value FROM logins; CryptUnprotectData
Agent Tesla can gather credentials from a number of browsers... APT3 has used tools to dump passwords from browsers... APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
This update has also fixed the issue where the malware fails to reconnect to a C&C server for a few days.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
Adversaries may use a non-application layer protocol for communication between host and C2 server or among infected hosts within a network. Specific examples include use of network layer protocols, such as the Internet Control Message Protocol (ICMP), transport layer protocols, such as the User Datagram Protocol (UDP), session layer protocols, such as Socket Secure (SOCKS), as well as redirected/tunneled protocols, such as Serial over LAN (SOL).
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
Appendix B: List of C&C servers www.google.com.dns-report.com microsoft.com.appstore.dynamicdns.co.uk cartview.viamisoftware.com
74 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
48 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor malware capable of injecting code into multiple Windows and browser processes.
Can use ICMP to receive destination-server information.
Malware used by BlackTech and found on the attacker-controlled server alongside the BIG-IP exploit code.
Identifies the IP address of infected hosts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.