PLEAD
MITRE ATT&CK: S0435 View on attack.mitre.org
Aliases: PLEAD
- First seen
- 2017-03-01 00:00:00
- Malware type
- rat, downloader
- Family
- Malware family
- Operating systems
- windows
- Last IoC activity
- 2026-04-10 01:57:06
- Profile updated
- 2026-07-07 12:55:38
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:tw country_code:jp country_code:hk
Context
PLEAD is a remote access tool (RAT) and downloader used by BlackTech in targeted attacks in East Asia including Taiwan, Japan, and Hong Kong. PLEAD has also been referred to as TSCookie, though more recent reporting indicates likely separation between the two. PLEAD was observed in use as early as March 2017.
Detection coverage
- 2 YARA rules
- 248 Sigma rules
Malware & tools used
- Web Protocols (attack-pattern)
- Windows Command Shell (attack-pattern)
- Credentials from Password Stores (attack-pattern)
- Proxy (attack-pattern)
- Malicious File (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Junk Data (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- File Deletion (attack-pattern)
- Malicious Link (attack-pattern)
- Native API (attack-pattern)
- Process Discovery (attack-pattern)
- Application Window Discovery (attack-pattern)
- Symmetric Cryptography (attack-pattern)
- Credentials from Web Browsers (attack-pattern)
Used by threat actors
- BlackTech (threat-actor)
Detection rules
- DITEKSHEN_MALWARE_Linux_PLEAD (yara-rule)
- MALPEDIA_Win_Plead_Auto (yara-rule)
Reports & references
- Trend Micro — Following Trail Blacktech Cyber Espionage Campaigns (report)
- MITRE ATT&CK — S0435 (report)
- Trend Micro — Plead Targeted Attacks Against Taiwanese Government Agencies 2 (report)
- blogs.jpcert.or.jp — Malware Tscooki 7Aa0 (report)