logo

Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data

ID: 75411947-1be1-4c4a-ae5e-dca8f3fee951

STIX ID: report--75411947-1be1-4c4a-ae5e-dca8f3fee951

Threat Score

85/100

Uploaded: 2026-08-19

Published Date: 2019-12-05

Last Modified Date: 2019-12-05

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Trend Micro's report documents the TICK cyberespionage group and its Operation ENDTRADE campaign, detailing a suite of multi-stage malware families (ABK, BBK, Avenger, down_new, Tomato, Snack, among others) used to steal proprietary and classified data from Japanese organizations and subsidiaries in China, employing spearphishing, AV evasion, steganography, and carefully crafted C2 infrastructure; the analysis maps the techniques to MITRE ATT&CK, provides IoCs, and highlights ongoing development and expansion of capabilities.