TClient
Aliases: FIRESHADOW
- Malware type
- rat
- Family
- Malware family
- Profile updated
- 2026-07-07 15:22:28
Targeted industries: technology-and-telecommunications government-and-public-sector
Context
Steve Miller pointed out that it is proxy-aware (Tencent) for C&C communication and uses wolfSSL, which makes it stick out.
Detection coverage
- 2 YARA rules
Detection rules
- CAPE_Tclient (yara-rule)
- MALPEDIA_Win_Tclient_Auto (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Tclient (report)
- twitter.com — 1266050369370677249 (report)