TClient

Aliases: FIRESHADOW

Malware type
rat
Family
Malware family
Profile updated
2026-07-07 15:22:28

Targeted industries: technology-and-telecommunications government-and-public-sector

Context

Steve Miller pointed out that it is proxy-aware (Tencent) for C&C communication and uses wolfSSL, which makes it stick out.

Detection coverage

  • 2 YARA rules

Detection rules

  • CAPE_Tclient (yara-rule)
  • MALPEDIA_Win_Tclient_Auto (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Tclient (report)
  • twitter.com — 1266050369370677249 (report)

External references