BS2005 is a Windows backdoor used by the China-linked cyberespionage group Ke3chang, also tracked as APT15 and Flea. Observed activity dates to at least 2012. It provides remote access to compromised systems and supports operator-directed post-exploitation. Its command-and-control communications use HTTP, with Base64-encoded data in request bodies. Documented implementations communicate through Internet Explorer's IWebBrowser2 COM interface, which can cause command-and-control data to be cached on disk. BS2005 also modifies Internet Explorer settings to disable Enhanced Security Configuration. Operators have established persistence using external batch scripts and Windows logon autorun mechanisms.
BS2005 was deployed through spear-phishing against European foreign ministries in August 2013, using Syria-crisis lures ahead of the St. Petersburg G20 summit. It was also present alongside RoyalCli and RoyalDNS during a 2017 compromise of a UK government services provider involving theft of sensitive government and military-related documents. The family forms part of a long-running malware lineage: Ketrican and RoyalCli evolved from BS2005, TidePool shares code and behavior with it, and Graphican subsequently evolved from Ketrican. Microsoft Graph API and OneDrive functionality belongs to Graphican rather than the original BS2005 backdoor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Ketrican, which itself was based on a previous malware—BS2005—that was also used by Flea.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
TidePool gathers information about the victim's computer, base64 encodes the data, and sends it to the Command and Control (C2) server via HTTP... The Base64 encoded data contains information about the victim’s service pack level, the current user, and the NETBIOS name of the victim system.
BS2005 uses Base64 encoding for communication in the message body of an HTTP request... Helminth encodes data with base64 and sends it via the "Cookie" field of HTTP requests. For C2 over DNS, Helminth converts ASCII characters into their hexadecimal values... RDAT can communicate with the C2 via base32-encoded subdomains.
The TidePool sample then sends victim computer information to the C2 server... POST http : //goback.strangled.net:443/QCLDDMGXVXESLYT HTTP/1.1
44 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Desktop backdoor used in diplomatic espionage against European foreign ministries. Also used alongside RoyalCli and RoyalDNS in the compromise of a UK contractor serving government customers.
BS2005 is a backdoor malware family used by APT15 for remote access and control of compromised systems, enabling espionage operations.
Backdoor malware family associated with APT15/Ke3chang, with minor functional variants across family members.
Earlier malware family used by Flea and forming the lineage behind Ketrican and Graphican.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.