SecondHandTea

First seen
2022-07-01 00:00:00
Malware type
rat
Family
Malware family
Profile updated
2026-07-07 13:09:06

Targeted industries: financial-services technology-and-telecommunications

Context

SecondHandTea is a full-featured Remote Access Trojan (RAT), closely related to BackbitingTea, the flagship backdoor used in the DangerousPassword campaigns (also known as SnatchCrypto). Both malware families appear to share a common codebase and are compiled within the same build environment. While they share most core functionality and supported commands, SecondHandTea differs from BackbitingTea variants in several technical aspects: - Configuration file paths - Network libraries: OpenSSL 1.1.0f vs. wolfSSL or Winsock TCP/IP - Encryption algorithms: AES-256 vs. RC4 - Compression methods: LZ4 vs. ZIP These differences suggest active development and customization efforts tailored to specific operational needs. The malware's name was inferred from its internal filename: SecondT_x64.exe. Between H2 2022 and Q1 2023, SecondHandTea was observed in targeted attacks against entities involved in cryptotrading and blockchain technology, indicating a continued focus on financially motivated cyber operations.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Secondhandtea_Auto (yara-rule)

Reports & references

  • web-assets.esetstatic.com — Eset Apt Activity Report T32022 (report)
  • virusbulletin.com — Lazarus Campaigns And Backdoors In 2022 2023 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Secondhandtea (report)

External references