TSCookieRAT

First seen
2017-02-01 00:00:00
Malware type
rat
Profile updated
2026-07-07 15:41:50

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:jp

Context

TSCookie provides parameters such as C&C server information when loading TSCookieRAT. Upon the execution, information of the infected host is sent with HTTP POST request to an external server. (The HTTP header format is the same as TSCookie.) The data is RC4-encrypted from the beginning to 0x14 (the key is Date header value), which is followed by the information of the infected host (host name, user name, OS version, etc.). Please refer to Appendix C, Table C-1 for the data format.

Reports & references

  • blog.jpcert.or.jp — Malware Tscooki 7Aa0 (report)

External references