Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data
ID: 75411947-1be1-4c4a-ae5e-dca8f3fee951
STIX ID: report--75411947-1be1-4c4a-ae5e-dca8f3fee951
Threat Score
85/100
Uploaded: 2026-08-19
Published Date: 2019-12-05
Last Modified Date: 2019-12-05
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Trend Micro's report documents the TICK cyberespionage group and its Operation ENDTRADE campaign, detailing a suite of multi-stage malware families (ABK, BBK, Avenger, down_new, Tomato, Snack, among others) used to steal proprietary and classified data from Japanese organizations and subsidiaries in China, employing spearphishing, AV evasion, steganography, and carefully crafted C2 infrastructure; the analysis maps the techniques to MITRE ATT&CK, provides IoCs, and highlights ongoing development and expansion of capabilities.
