Operation Ke3chang Resurfaces With New TidePool Malware
ID: f9c6003d-07bf-450b-8c41-6ca5ff74a04c
STIX ID: report--f9c6003d-07bf-450b-8c41-6ca5ff74a04c
Threat Score
85/100
Uploaded: 2026-08-07
Published Date: 2016-06-01
Last Modified Date: 2016-06-01
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Unit 42 reports the discovery of TidePool, a new RAT used in an ongoing campaign likely tied to the Ke3chang APT; the attackers weaponize MHTML documents to exploit CVE-2015-2545, drop a DLL for persistence (rundll32 via ActiveSetup), modify IE-related registry keys to weaken protection, and exfiltrate host data to a C2 (goback.strangled.net). The report documents code reuse linking TidePool to the BS2005 family, lists numerous sample hashes and phishing/weaponized-doc IOCs, and outlines attribution evidence and targeted victims (Indian embassies).
