TidePool is a Windows remote access trojan associated with the China-linked espionage group APT15, also known as Ke3chang. It is regarded as part of the broader BS2005 malware lineage and has been used in cyberespionage operations against diplomatic targets, most notably Indian embassy personnel worldwide. TidePool has also appeared in activity attributed to DragonOK, indicating reuse or overlap in delivery tradecraft across Chinese espionage operations.
TidePool provides core RAT functionality for interactive post-compromise control. Documented capabilities include collecting victim system information, transmitting that data over HTTP after base64 encoding, receiving commands from a command-and-control server, reading, writing, and deleting files and folders, and executing commands through named pipes. Its behavior and code show overlap with earlier Ke3chang tooling, including similar command-and-control obfuscation, beacon construction, and registry modification patterns.
A well-documented delivery method used weaponized MHTML documents exploiting CVE-2015-2545 in Microsoft Word. In campaigns against Indian diplomatic personnel, these lures were delivered via spearphishing emails that spoofed legitimate embassy-associated individuals. Separate reporting also links TidePool delivery to malicious RTF-based exploitation activity used by DragonOK, alongside IsSpace and Sysget malware.
On infected systems, TidePool establishes persistence through the Active Setup mechanism after dropping a DLL payload to disk. The malware’s operational profile is consistent with long-running Chinese state-aligned espionage activity focused on diplomatic and government entities. TidePool is best understood as an evolutionary BS2005-derived backdoor used for sustained access, operator-driven tasking, and information collection on compromised Windows hosts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Sysget malware was delivered both directly via phishing emails, as well as in Rich Text Format (RTF) documents exploiting the CVE-2015-1641 vulnerability (patched in MS15-033) that in turn leveraged a very unique shellcode.
The weaponized document sent in phishing emails triggers the vulnerability outlined in CVE-2015-2545, which was first made public in September 2015... The TidePool malware is housed in an MHTML document which exploits CVE-2015-2545. | We’ve discovered a new malware family we’ve named TidePool. It has strong behavioral ties to Ke3chang and is being used in an ongoing attack campaign against Indian embassy personnel worldwide.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Ke3chang’s numerous tools such as Okrum, Ketrican, TidePool, Mirage, Ketrum, and others all serve the same purpose...
Additionally, we have observed instances of the IsSpace and TidePool malware families being delivered via the same techniques.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
TidePool gathers information about the victim's computer, base64 encodes the data, and sends it to the Command and Control (C2) server via HTTP... The Base64 encoded data contains information about the victim’s service pack level, the current user, and the NETBIOS name of the victim system.
52 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
TidePool is a backdoor malware, evolved from BS2005, used by APT15 for espionage against diplomatic targets.
Trojan with RAT-like capabilities that can manipulate files, execute commands via named pipes, gather host information, encode data in base64, and exfiltrate it over HTTP.
Named as one of several Ke3chang tools under the broader BS2005 malware umbrella.
A related malware family mentioned for comparison and linkage to Ke3chang activity, targeting Indian embassies globally.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.