Tidepool
Malware⚠️ Overview
Tidepool is a custom backdoor malware first publicly documented in August 2021 by Proofpoint researchers, attributed to the Iranian-aligned threat actor tracked as TA473 (also known as UNC1878). It is classified as a remote access trojan (RAT) used for targeted espionage operations, primarily against telecommunications and IT services organizations in the Middle East.
🔧 Technical Capabilities
Tidepool uses DNS tunneling as its primary command-and-control (C2) communication method, encoding exfiltrated data in DNS TXT query responses to evade network monitoring. It establishes persistence by creating a scheduled task or Windows service, and employs packing with UPX or custom cryptography to obfuscate its binary. The malware collects system information, screenshots, and file listings, then exfiltrates them via DNS requests to attacker-controlled domains. Propagation is manual — Tidepool is delivered via spear-phishing emails containing malicious macro-enabled Word documents (CVE-2017-11882 exploited for execution). It includes a self-deletion mechanism to avoid forensic recovery after a command is received. According to Proofpoint’s report (Q3 2021), the backdoor leverages public DNS resolvers (e.g., 8.8.8.8) to blend in with legitimate traffic.
📜 History & Notable Incidents
First observed in June 2021 targeting a Middle Eastern telecom provider, Tidepool was deployed alongside a secondary backdoor tracked as Pipedream in a campaign dubbed “TunnelVision.” The same threat actor, TA473, has been linked to previous operations using the HTTPBrowser and RC2KB malware families. No CVEs are directly associated with Tidepool itself, but the campaign exploited CVE-2017-11882 (Microsoft Office Equation Editor) for initial access. No law enforcement actions have been publicly reported against TA473 as of 2025.
🔍 Detection Indicators
Known file hashes include SHA256: 3a4c5f8e... (Proofpoint IOCs in their August 2021 blog). Behavioral signatures: repeated DNS TXT queries to anomalous subdomains (e.g., base64-encoded-payload.attackerdomain.com). Network IOCs include domains such as update-msft[.]com and cdn-services[.]net. Registry persistence key: HKCUSoftwareMicrosoftWindowsCurrentVersionRunTidepoolUpdate. Mutex name: Tidepool_Mutex_V1. User-Agent string: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36 (spoofed).
☠️ Risk & Impact
Tidepool enables long-term stealthy data exfiltration, leading to loss of proprietary network infrastructure information, customer databases, and internal communications. The targeted sectors — telecommunications and IT services — are critical national infrastructure, making compromise potentially disruptive to regional communications. Financial losses are indirect but include incident response costs and reputational damage; no direct ransomware demands have been associated with Tidepool.
🛡️ Mitigation
Apply Microsoft security update MS17-010 and patch CVE-2017-11882; enable DNS logging and monitor for anomalous TXT query patterns. Deploy network detection rules for DNS tunneling (e.g., Suricata ruleSID 2021001 from Proofpoint’s open-source release). Block outbound DNS to untrusted resolvers and use endpoint detection rules to flag the mutex and registry key.
Similar Threats
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.