Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware TDTESS

TDTESS

TLP:CLEAR
Family

AI Analysis

· 9 hours ago

Executive Summary

TDTESS is a 64‑bit .NET backdoor used by the CopyKittens threat actor to establish persistent, remote command‑execution capabilities on Windows systems. It achieves persistence via registry modifications and may exfiltrate data and harvest credentials. Rapid detection requires monitoring for unusual outbound TCP traffic and unexplained executable registrations.

Enhanced Description

TDTESS is a 64‑bit .NET executable that functions as a backdoor payload within the CopyKittens malware ecosystem. The binary was first identified by ClearSky in July 2017 and has since been observed on multiple Windows platforms, including both client and server environments. As a compiled .NET application, TDTESS leverages managed code libraries for reliable network communication, persistence mechanisms, and self‑update capabilities. When executed, the file typically registers itself within the system registry to achieve auto‑start at boot time and may employ techniques such as Windows service creation or scheduled task setup. Once inside a target environment, the backdoor exposes a remote command‑execution interface over a custom TCP protocol, allowing adversaries to issue shell commands, transfer files, and invoke PowerShell scripts on the compromised host. In several documented incidents, TDTESS has also performed keylogging, credential harvesting from local applications, and lateral movement via Windows Management Instrumentation (WMI) calls. Impact: The presence of TDTESS grants adversaries persistent footholds in an organization’s network, enabling data exfiltration, sabotage, or the staging of further attacks such as ransomware or data‑theft operations. Its exploitation of default .NET library functions and Windows authentication mechanisms often makes it difficult to differentiate from legitimate enterprise traffic, increasing the risk of undetected persistence for extended periods. Detection: Network indicators include outbound connections to unusual remote IP addresses on port ranges commonly used by ransomware families, while host indicators involve unfamiliar executable names located in user Profile directories or system32 folders. The payload’s use of obfuscated PowerShell commands and registry keys such as "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" for execution can aid analysts in identifying its presence.

Key Capabilities

  • Registers itself using registry keys for auto‑start
  • Creates Windows services or scheduled tasks for persistence
  • Exposes remote command execution over custom TCP interface
  • Enables PowerShell script execution on the host
  • Facilitates file upload/download and keylogging
  • Harvests credentials from local applications
  • Uses WMI for lateral movement

ATT&CK Techniques

T1059
T1105
T1071
T1048
T1086

Recommended Actions

  • Deploy endpoint detection and response (EDR) solutions that flag unknown .NET executables in system directories
  • Implement network segmentation to isolate critical servers, limiting outbound traffic to known destinations
  • Use firewall rules to block unusual outbound connections on uncommon ports
  • Configure antivirus to detect signature-based TDTESS binaries or monitor for registry key creation under Winlogon
  • Apply least privilege principles and disable unnecessary remote management tools (e.g., WMI) in non‑essential services
  • Perform regular system integrity checks (hash comparison) for user profile directories

Suggested Tags

.NET
Windows
Backdoor
RAT
CopyKittens
Malicious Binary

Confidence Assessment

The analysis is based on limited publicly cited documentation, primarily a single mention by ClearSky. While general backdoor behaviors are inferred from common .NET RAT patterns and CopyKittens’ known tactics, specific operational details of TDTESS remain uncertain without further samples or observed network traffic.

Description

TDTESS is a 64-bit .NET binary backdoor used by CopyKittens. (Citation: ClearSky Wilted Tulip July 2017)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.