Tidepool

First seen
2020-03-15 00:00:00
Malware type
backdoor, rat
Family
Malware family
Profile updated
2026-07-07 12:39:45

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

Tidepool is a sophisticated remote access trojan (RAT) commonly used for cyber espionage activities. It is designed to target governmental and technological sectors, providing attackers with remote access and control. The malware often uses advanced persistence techniques to remain undetected on compromised systems.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Tidepool_Auto (yara-rule)

Reports & references

  • Mandiant — Wp Operation Ke3Chang (report)
  • Palo Alto Unit 42 — Shallowtaurus (report)
  • Mandiant — Operation Ke3Chang Targeted Attacks Against Ministries Of Foreign Affairs (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Tidepool (report)
  • researchcenter.paloaltonetworks.com — Operation Ke3Chang Resurfaces With New Tidepool Malware (report)

External references