Description
PLEAD is a remote access tool and downloader used by the BlackTech threat actor in targeted attacks in East Asia, including Taiwan, Japan, and Hong Kong, observed since as early as March 2017. Reporting initially conflated it with the TSCookie family, though researchers now treat the two as likely separate.
Stats
- First seen
- March 2022
- Last seen
- September 2026
Also known as
PLeadPlead
MITRE ATT&CK techniques
15 techniques across 5 tactics.
TA0002 Execution
TA0007 Discovery
Associated groups
Alert name variants
| Alert Name |
|---|
| Linux.Backdoor.Plead |
| Linux.Trojan.PLead |
| Win32.Backdoor.Plead |
| Win32.Trojan.Plead |