logo

Operation Ke3chang Resurfaces With New TidePool Malware

ID: f9c6003d-07bf-450b-8c41-6ca5ff74a04c

STIX ID: report--f9c6003d-07bf-450b-8c41-6ca5ff74a04c

Threat Score

85/100

Uploaded: 2026-08-07

Published Date: 2016-06-01

Last Modified Date: 2016-06-01

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Unit 42 reports the discovery of TidePool, a new RAT used in an ongoing campaign likely tied to the Ke3chang APT; the attackers weaponize MHTML documents to exploit CVE-2015-2545, drop a DLL for persistence (rundll32 via ActiveSetup), modify IE-related registry keys to weaken protection, and exfiltrate host data to a C2 (goback.strangled.net). The report documents code reuse linking TidePool to the BS2005 family, lists numerous sample hashes and phishing/weaponized-doc IOCs, and outlines attribution evidence and targeted victims (Indian embassies).