Tidepool
- First seen
- 2020-03-15 00:00:00
- Malware type
- backdoor, rat
- Family
- Malware family
- Profile updated
- 2026-07-07 12:39:45
Targeted industries: government-and-public-sector technology-and-telecommunications
Context
Tidepool is a sophisticated remote access trojan (RAT) commonly used for cyber espionage activities. It is designed to target governmental and technological sectors, providing attackers with remote access and control. The malware often uses advanced persistence techniques to remain undetected on compromised systems.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Tidepool_Auto (yara-rule)
Reports & references
- Mandiant — Wp Operation Ke3Chang (report)
- Palo Alto Unit 42 — Shallowtaurus (report)
- Mandiant — Operation Ke3Chang Targeted Attacks Against Ministries Of Foreign Affairs (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Tidepool (report)
- researchcenter.paloaltonetworks.com — Operation Ke3Chang Resurfaces With New Tidepool Malware (report)