Netskope Threat Labs

PLEAD

ATP Sandbox Adv. Heuristics

PLEAD is a remote access tool and downloader used by the BlackTech threat actor in targeted attacks in East Asia, including Taiwan, Japan, and Hong Kong, observed since as early as March 2017. Reporting initially conflated it with the TSCookie family, though researchers now treat the two as likely separate.

First seen
March 2022
Last seen
September 2026
PLeadPlead

15 techniques across 5 tactics.

TA0002 Execution

TA0005 Stealth

TA0006 Credential Access

  • T1555Credentials from Password Stores

TA0007 Discovery

  • T1010Application Window Discovery
  • T1057Process Discovery
  • T1083File and Directory Discovery

TA0011 Command and Control

Alert Name
Linux.Backdoor.Plead
Linux.Trojan.PLead
Win32.Backdoor.Plead
Win32.Trojan.Plead