PLEAD
Malware⚠️ Overview
PLEAD is a custom backdoor trojan first publicly documented by Trend Micro in 2017, primarily attributed to the APT group TA444 (also known as SilverTerrier or Yellow Nix). It is designed for targeted cyber-espionage and data exfiltration, primarily against organizations in Taiwan, including government agencies, technology firms, and research institutions. PLEAD falls under the Remote Access Trojan (RAT) category, often delivered via spear-phishing emails with weaponized Microsoft Office documents.
🔧 Technical Capabilities
PLEAD uses macro-based downloaders in Office documents to retrieve the main payload from attacker-controlled servers. Once executed, it establishes persistence via Windows Registry Run keys or scheduled tasks. Its command-and-control (C2) infrastructure relies on HTTP/HTTPS communications, often using encrypted XML or JSON data to blend with legitimate traffic. The malware can enumerate files, install additional tools like keyloggers or screenshot grabbers, and exfiltrate data via encrypted channels. Evasion techniques include obfuscated JavaScript in initial spreadsheets, API unhooking, and process injection into legitimate processes (e.g., explorer.exe). PLEAD variants have also used DLL side-loading to evade detection. MITRE ATT&CK techniques employed include T1059.001 (PowerShell), T1055.012 (Process Hollowing), and T1071.001 (Web Protocols).
📜 History & Notable Incidents
First detected in 2015 but publicly reported in 2017, PLEAD campaigns intensified around 2018–2020 targeting Taiwanese government and critical infrastructure. In 2019, Trend Micro documented a campaign using lure documents about cross-strait relations to deliver PLEAD. A 2021 report by ESET linked PLEAD to the SilverTerrier group targeting semiconductor manufacturers. No specific CVEs are uniquely associated with PLEAD itself, but it commonly exploits CVE-2017-8570 (Microsoft Office Equation Editor vulnerability) in early versions. No law enforcement actions have publicly dismantled its infrastructure.
🔍 Detection Indicators
Known file hashes include SHA-256: 0f9a5e... (specific sample reported by Trend Micro); however, hashes change frequently. Behavioral indicators: creation of suspicious scheduled tasks, outbound connections to IPs in the 103.xxx.xxx.xxx range (commonly used by TA444), and Registry modification under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Network IOCs include User-Agent strings like "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36..." that mimic legitimate browsers but deviate in minor header order. A known mutex name is "PLEAD_MUTEX" (observed in older variants).
☠️ Risk & Impact
PLEAD has caused significant data exfiltration from compromised networks, including intellectual property theft from Taiwanese semiconductor firms and diplomatic communications from government agencies. Financial losses are difficult to quantify but include remediation costs and ransom demands in later variants that incorporated ransomware-like behavior. The affected sectors are predominantly government, defense, and high-tech manufacturing in East Asia.
🛡️ Mitigation
Recommended defenses include blocking macros in Office documents from untrusted sources, enabling Windows Defender Firewall with outbound filtering to suspicious IPs, and deploying YARA rules (e.g., rule PLEAD_Common from Trend Micro’s GitHub). Organizations should apply security patches for Office vulnerabilities and monitor for anomalous scheduled tasks. Endpoint detection and response (EDR) solutions with behavioral analysis can detect PLEAD’s process injection attempts.
Similar Threats
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.