PLEAD

MITRE ATT&CK: S0435 View on attack.mitre.org

Aliases: PLEAD

First seen
2017-03-01 00:00:00
Malware type
rat, downloader
Family
Malware family
Operating systems
windows
Last IoC activity
2026-04-10 01:57:06
Profile updated
2026-07-07 12:55:38

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:tw country_code:jp country_code:hk

Context

PLEAD is a remote access tool (RAT) and downloader used by BlackTech in targeted attacks in East Asia including Taiwan, Japan, and Hong Kong. PLEAD has also been referred to as TSCookie, though more recent reporting indicates likely separation between the two. PLEAD was observed in use as early as March 2017.

Detection coverage

  • 2 YARA rules
  • 248 Sigma rules

Malware & tools used

  • Web Protocols (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Credentials from Password Stores (attack-pattern)
  • Proxy (attack-pattern)
  • Malicious File (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Junk Data (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • File Deletion (attack-pattern)
  • Malicious Link (attack-pattern)
  • Native API (attack-pattern)
  • Process Discovery (attack-pattern)
  • Application Window Discovery (attack-pattern)
  • Symmetric Cryptography (attack-pattern)
  • Credentials from Web Browsers (attack-pattern)

Used by threat actors

Detection rules

  • DITEKSHEN_MALWARE_Linux_PLEAD (yara-rule)
  • MALPEDIA_Win_Plead_Auto (yara-rule)

Reports & references

  • Trend Micro — Following Trail Blacktech Cyber Espionage Campaigns (report)
  • MITRE ATT&CK — S0435 (report)
  • Trend Micro — Plead Targeted Attacks Against Taiwanese Government Agencies 2 (report)
  • blogs.jpcert.or.jp — Malware Tscooki 7Aa0 (report)

External references