Executive Summary
T9000 is a Windows backdoor belonging to the T5000/Plat1 family, engineered to covertly harvest system and network metadata for use in targeted operations. First seen by security firms in 2014‑2016, it has been linked to attacks on U.S. organizations that rely heavily on discreet reconnaissance.
Enhanced Description
T9000 is a sophisticated Windows backdoor that represents the latest iteration of the well‑known T5000/Plat1 family. First reported to FireEye in March 2014 and later observed by Palo Alto Networks in February 2016, the malware has been deployed in several high‑profile targeted campaigns against U.S. organizations. Once installed it quietly gathers extensive system reconnaissance data—including operating system version, installed software, user accounts, running processes, and network configuration—and forwards this information to a command‑and‑control (C&C) server over encrypted HTTP/S channels. The collected intelligence is used by adversaries to assess the technical maturity of their targets, identify potential pivot points, and craft subsequent attacks. T9000 establishes persistence through registry Run keys and optionally scheduled tasks, allowing it to survive reboots without user interaction. Its modular design suggests that additional command modules (e.g., for credential dumping or lateral movement) can be pushed remotely, but the publicly available data indicates that its core functionality centers on stealthy information acquisition rather than aggressive payload delivery.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
The available intelligence largely derives from incident reports by FireEye and Palo Alto Networks with limited technical detail. While core behaviors—information gathering and C&C communication—are well documented, specific command sets, file names, and unique indicators of compromise remain underreported. Additional analysis of malware samples, network captures, and IOC repositories is required to achieve higher confidence levels.
T9000 is a backdoor that is a newer variant of the T5000 malware family, also known as Plat1. Its primary function is to gather information about the victim. It has been used in multiple targeted attacks against U.S.-based organizations. (Citation: FireEye admin@338 March 2014) (Citation: Palo Alto T9000 Feb 2016)