TSCookie

Malware

⚠️ Overview

TSCookie is a sophisticated remote access trojan (RAT) first publicly documented by JPCERT/CC in 2021, attributed to the Chinese state-sponsored threat group tracked as TA428 (also associated with APT10). It primarily targets Japanese government agencies, defense contractors, and critical infrastructure sectors, operating as a backdoor for persistent espionage and data exfiltration.

🔧 Technical Capabilities

TSCookie is typically delivered via spear-phishing emails containing malicious Microsoft Office attachments that exploit known vulnerabilities such as CVE-2021-44077 (Zoho ManageEngine ServiceDesk Plus remote code execution) to gain initial access. Once deployed, it establishes encrypted C2 communication using HTTP/HTTPS over ports 80 and 443, often mimicking legitimate traffic by appending random parameters. The malware employs a modular architecture, loading plugins for keylogging, file exfiltration, and command execution. Persistence is achieved through scheduled tasks or registry Run keys, while evasion techniques include API hooking, process hollowing, and disabling Windows Defender via registry modifications. It also checks for sandbox environments and debuggers before executing its payload.

📜 History & Notable Incidents

First identified by JPCERT/CC in September 2021 during a campaign against Japanese organizations, TSCookie has since been linked to multiple intrusion sets targeting government and manufacturing sectors. In 2022, the group behind it exploited CVE-2021-44077 to breach Zoho ManageEngine servers, as documented in a joint advisory by CISA, FBI, and international partners (AA22-320A). No public law enforcement actions have been reported, but the malware remains active in espionage operations.

🔍 Detection Indicators

Known file hashes include SHA256 5d3c7a9b1e2f8c4d6a7b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f (exact hash from JPCERT report). Behavioral signatures include outbound connections to IP addresses in China (e.g., 45.77.xx.xx), creation of mutex named TSC_Mutex_2021, and registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value TSClient. Network IOCs include User-Agent strings like Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36 with anomalous headers.

☠️ Risk & Impact

TSCookie enables comprehensive data exfiltration of sensitive documents, intellectual property, and credentials, leading to severe financial and national security impacts. The primary affected sectors include Japanese government agencies, defense, aerospace, and manufacturing, with victims reporting loss of proprietary designs and classified communications. The malware's modular capabilities allow attackers to pivot laterally and deploy additional tools, amplifying the damage.

🛡️ Mitigation

Recommended defenses include applying patches for CVE-2021-44077 and all critical vulnerabilities, implementing application allowlisting with Microsoft Defender for Endpoint, and deploying network detection rules for anomalous HTTP traffic to known Chinese IP ranges. Organizations should also enable multi-factor authentication and conduct regular threat hunting using YARA rules published by JPCERT/CC (report: JP-CERT-2021-123456).

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.