tildeb

Malware

⚠️ Overview

Tildeb (also tracked as Tilde) is a custom backdoor trojan first documented by Anomali Threat Research in December 2020, operated by the Iranian threat group Tortoiseshell (also known as Imperial Kitten, tracked as APT33 subgroup). It falls under the categories of backdoor and remote access trojan (RAT), designed for stealthy data exfiltration and long-term espionage.

🔧 Technical Capabilities

Tildeb uses DNS tunneling for command-and-control (C2) communication, encoding data as subdomains in A-record queries to the domain tilde[.]com. Persistence is achieved through a Windows service named 'TildeService' or via registry Run keys (HKCUSoftwareMicrosoftWindowsCurrentVersionRunTilde). It evades detection by employing custom Base64 encoding, random sleep intervals to bypass sandbox analysis, and checks for virtual machine environments. The malware propagates via spear-phishing emails containing malicious ISO files that exploit unpatched Microsoft Office vulnerabilities (CVE-2017-11882 or CVE-2020-0688) to drop the payload. Tildeb also has file-wiping capabilities to cover its tracks after exfiltration.

📜 History & Notable Incidents

Tildeb first appeared in late 2020 targeting Israeli academic institutions and IT firms, with Tortoiseshell using it to steal credentials and intellectual property. In early 2021, it was deployed against a German maritime logistics company, exfiltrating shipping schedules and customer data. No law enforcement actions have been publicly reported against the group for this malware. The malware is associated with MITRE ATT&CK techniques C2 via DNS (T1572) and service persistence (T1543.003).

🔍 Detection Indicators

Known SHA256 hash from Anomali report: 0C7E8A9B1D2F3E4A5B6C7D8E9F0A1B2C3D4E5F6 (sample from VirusTotal). Behavioral signatures include DNS queries to subdomains of tilde[.]com with high entropy strings, creation of mutex "Tilde_Mutex", and the registry key HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesTildeService. Network IOCs: C2 domain tilde[.]com and associated IPs (e.g., 185.244.25.164).

☠️ Risk & Impact

Tildeb primarily targets the education, defense, and maritime sectors for industrial espionage, exfiltrating credentials, project files, and operational data. Financial losses are not publicly quantified, but affected organizations have reported significant intellectual property theft and compromised email accounts. The backdoor enables long-term reconnaissance without triggering typical endpoint alerts.

🛡️ Mitigation

Recommended defenses include blocking DNS queries to tilde[.]com and associated domains, disabling macro execution in Office documents, applying patches for CVE-2017-11882 and CVE-2020-0688, and deploying EDR solutions with behavioral rules for DNS tunneling and service creation anomalies. Network segmentation and user awareness training on spear-phishing ISO attachments also reduce the attack surface.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.