BS2005 is a long-running Windows backdoor family associated with the China-linked espionage group APT15, also known as Ke3chang. It has been observed since at least the early 2010s and forms part of a broader lineage of related APT15 tooling that includes Ketrican, TidePool, RoyalCli, Okrum, Ketrum, and later Graphican. Multiple analyses treat these families as evolutionary variants or closely related descendants under the same operational umbrella, reflecting the actor’s pattern of reusing and incrementally modifying established implants rather than replacing them outright.
BS2005 is used for remote operator-controlled access in espionage intrusions. Reported functionality and closely linked evolutions indicate support for core backdoor operations such as command execution, file upload and download, victim system information collection, persistence, and post-compromise tasking. In documented APT15 operations, BS2005 appeared alongside companion tooling for credential theft, keylogging, reconnaissance, lateral movement, and data theft, although those auxiliary capabilities were not necessarily embedded in every BS2005 sample itself.
A distinctive trait of BS2005 is its HTTP-based command-and-control traffic, including Base64-encoded data placed in the body of HTTP requests. In some operations, BS2005 communicated through Internet Explorer via the IWebBrowser2 COM interface, a technique that helped blend malicious traffic with legitimate browser activity. Related APT15 variants derived from or evolving from BS2005 retained similar communication obfuscation and beaconing logic.
BS2005 has been tied to sustained cyber-espionage campaigns against diplomatic, government, military, and foreign affairs targets across Europe, Asia, and the Americas. It was historically used in Operation Ke3chang and later appeared in intrusions involving UK government service providers and other high-value organizations. Delivery has been observed in broader APT15 spearphishing campaigns through weaponized documents, while some incidents involving BS2005-family activity had unknown initial infection vectors. The malware family is best understood as a foundational APT15 backdoor lineage that has continuously evolved across multiple campaigns and successor implants.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
We can regard these tools under the same umbrella of BS2005 malware, distributed as different versions per operation.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
TidePool gathers information about the victim's computer, base64 encodes the data, and sends it to the Command and Control (C2) server via HTTP... The Base64 encoded data contains information about the victim’s service pack level, the current user, and the NETBIOS name of the victim system.
BS2005 uses Base64 encoding for communication in the message body of an HTTP request... Helminth encodes data with base64 and sends it via the "Cookie" field of HTTP requests. For C2 over DNS, Helminth converts ASCII characters into their hexadecimal values... RDAT can communicate with the C2 via base32-encoded subdomains.
The TidePool sample then sends victim computer information to the C2 server... POST http : //goback.strangled.net:443/QCLDDMGXVXESLYT HTTP/1.1
44 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
BS2005 is a backdoor malware family used by APT15 for remote access and control of compromised systems, enabling espionage operations.
Backdoor malware family associated with APT15/Ke3chang, with minor functional variants across family members.
Earlier malware family used by Flea and forming the lineage behind Ketrican and Graphican.
Malware that uses Base64 in HTTP request bodies for command-and-control communication.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.