Threat reportMalwareTL-2026-2426

BloodAlchemy RAT Traced to Deed RAT/ShadowPad Lineage via VPN Account Compromise and DLL Side-Loading

highACTIVE

BloodAlchemy RAT Traced to Deed RAT/ShadowPad Lineage via (TL-2026-2426), also tracked as BLOODALCHEMY, is a high-severity malware campaign, first published 2026-09-10. It is attributed to REF5961 (China) with medium confidence, affects Brother Industries BrDifxapi.exe (device driver installer utility), maps to 18 MITRE ATT&CK techniques (T1027, T1027.011, T1053.005), and is covered by 9 detection rules and 20 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
18MITRE ATT&CK
Actors
1REF5961
Detection rules
9SPL · KQL · Sigma
IOCs
20Indicators of compromise

Key facts for TL-2026-2426

Threat ID
TL-2026-2426
Also known as
BLOODALCHEMY
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution
REF5961
Attribution confidence
MEDIUM
Nation-state nexus
China
Motivation
ESPIONAGE
Target sectors
government administration
Target regions
Southeast Asia, mongolia
Detection rules
9
Indicators of compromise
20

Malware and tooling in BloodAlchemy RAT Traced to Deed RAT/ShadowPad Lineage via

Malware and tooling: BloodAlchemy, PlugX, SNAPPYBEE, ShadowPad, ShadowPad (POISONPLUG.SHADOW), Voidoor, Acunetix, Portmap, ShadowPad

How BloodAlchemy RAT Traced to Deed RAT/ShadowPad Lineage via works

ITOCHU Cyber & Intelligence's code-level analysis of the BLOODALCHEMY backdoor (first named by Elastic Security Labs in October 2023 as part of the REF5961 intrusion set) traces it to Deed RAT, a backdoor exclusive to the Space Pirates actor, which in turn descends from ShadowPad and PlugX. Observed intrusions begin with a compromised VPN maintenance account and use DLL side-loading (BrDifxapi.exe loading BrLogAPI.dll) to run a fileless, AES/LZNT1-decrypted shellcode payload.

ITOCHU Cyber & Intelligence researchers (published 2024-05-23) analyzed BLOODALCHEMY, a Windows x86 remote access trojan first named by Elastic Security Labs in October 2023 as part of the China-nexus REF5961 intrusion set that targeted an ASEAN member state's Ministry of Foreign Affairs, with secondary targeting observed in Mongolia. ITOCHU's code-level analysis traced BLOODALCHEMY's lineage backward through Deed RAT -- a backdoor exclusively attributed to the Space Pirates threat actor and documented in depth by Positive Technologies -- to ShadowPad (aka POISONPLUG.SHADOW), itself the successor to PlugX/Korplug. The lineage is evidenced by near-identical custom (non-PE) payload header structures, matching plugin-ID/magic-number schemes, shared shellcode-loading routines, comparable exception-handling patterns immediately following the payload entry point, and reused hardcoded persistence directory/filenames ("Test") across BLOODALCHEMY and Deed RAT samples.

Observed intrusions begin with compromise of a victim's VPN maintenance/vendor-support account, giving the actor an initial foothold without exploiting any software vulnerability. From there, three files are dropped into C:\windows\: the legitimate but certificate-revoked Brother Industries utility BrDifxapi.exe, a malicious loader DLL (BrLogAPI.dll) that BrDifxapi.exe side-loads, and an AES-128-CBC-encrypted shellcode container named DIFX whose decryption key is the file's own first 16 bytes. BrLogAPI.dll decrypts DIFX, applies a custom FNV-1a-hash-based decryption pass, and LZNT1-decompresses the result via RtlDecompressBuffer to recover a non-standard, non-PE payload (magic number 45 AB 45 AB) that is mapped with VirtualAlloc and executed entirely in memory -- BLOODALCHEMY's payload never exists as a standalone file on disk. Persistence is established via a scheduled task at C:\Windows\System32\Tasks\Dell\BrDifxapi, a Windows service named "Test" (description "Digital Imaging System"), and/or a CurrentVersion\Run registry key, selectable through a persistence-mode flag in the malware's configuration.

BLOODALCHEMY implements 7 operational run modes (ranging from bare C2 beaconing to full persistence + injection + anti-analysis) and 15 backdoor commands covering configuration management, self-update of all three toolset components, uninstall, registry-resident payload storage, proxy configuration, and victim reconnaissance (CPU/OS/network). Code execution into legitimate host processes (SearchIndexer.exe, wininit.exe, taskhost.exe, svchost.exe, taskeng.exe) uses Early Bird APC-queue injection (WriteProcessMemory + QueueUserAPC + ResumeThread). A configuration flag optionally activates Trellix-sandbox-detection logic (process names, file artifacts, DNS results) before the implant fully activates. The malware's configuration supports up to 10 configurable C2 destinations across eight protocols (DNS, HTTP, HTTPS, MUX, UDP, SMB, SOCKS4/5, TCP), though the ITOCHU-analyzed sample used only one; configuration data is itself protected with a rotating single-byte XOR key.

ITOCHU's code lineage points to the same malware ecosystem behind Deed RAT/Space Pirates, while Elastic separately assesses REF5961 as a distinct but related China-nexus, espionage-motivated intrusion set with high confidence, based on tooling and infrastructure correlation with earlier REF2924 activity. Subsequent media coverage noted that the February 2024 leak of Chinese state contractor I-Soon's internal materials plausibly explains why these outwardly separate Chinese clusters (REF5961/BLOODALCHEMY and Space Pirates/Deed RAT) share deeply similar tooling: the leak points to hack-for-hire "digital quartermaster" entities that build and distribute a shared malware toolkit across multiple state-directed campaigns rather than each actor independently engineering its own implants. No CVE is associated with this threat -- the abused weakness is a compromised third-party VPN maintenance credential, not a software vulnerability.

MITRE ATT&CK techniques used in TL-2026-2426

Defense Evasion

T1027 Obfuscated Files or Information; T1027.011 Obfuscated Files or Information: Fileless Storage; T1055.004 Process Injection: Asynchronous Procedure Call; T1140 Deobfuscate/Decode Files or Information; T1497 Virtualization/Sandbox Evasion; T1574.001 DLL

Persistence

T1053.005 Scheduled Task/Job: Scheduled Task; T1543.003 Create or Modify System Process: Windows Service; T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder

Command and Control

T1071.001 Application Layer Protocol: Web Protocols; T1071.004 Application Layer Protocol: DNS; T1090 Proxy; T1095 Non-Application Layer Protocol

Initial Access

T1078 Valid Accounts; T1133 External Remote Services

Discovery

T1082 System Information Discovery

Execution

T1106 Native API

defense-impairment

T1112 Modify Registry

Affected products and versions in BloodAlchemy RAT Traced to Deed RAT/ShadowPad Lineage via

  • Brother Industries — BrDifxapi.exe (device driver installer utility)
    Vulnerable versions: signed release with a since-revoked code-signing certificate, abused as a DLL side-loading host

Remediation for BloodAlchemy RAT Traced to Deed RAT/ShadowPad Lineage via

Immediate actions

  • Audit and rotate credentials for all VPN maintenance/vendor-support accounts; enforce MFA on VPN administrative access
  • Hunt for BrDifxapi.exe co-located with BrLogAPI.dll and a DIFX file outside expected Brother Industries install paths, especially under C:\windows\
  • Alert on scheduled task creation under C:\Windows\System32\Tasks\Dell\BrDifxapi
  • Alert on Windows service creation named "Test" with description "Digital Imaging System"

Workarounds

  • Restrict execution of BrDifxapi.exe and other Brother Industries device-driver utilities to systems where legitimately required
  • Network-segment VPN maintenance/vendor-access channels away from core infrastructure and monitor their authentication logs closely

Longer-term hardening

  • Deploy EDR detection for QueueUserAPC/Early Bird APC-queue injection targeting SearchIndexer.exe, wininit.exe, taskhost.exe, svchost.exe, and taskeng.exe
  • Implement application control / code-signing allowlisting to catch DLL side-loading via binaries with revoked or otherwise anomalous signatures
  • Monitor for fileless shellcode execution patterns (VirtualAlloc following LZNT1 decompression via RtlDecompressBuffer)
  • Baseline and alert on unexpected writes to CurrentVersion\Run and other registry-resident payload storage locations

Timeline of BloodAlchemy RAT Traced to Deed RAT/ShadowPad Lineage via

  • ShadowPad, the earliest identifiable ancestor in BLOODALCHEMY's code lineage, is first identified after being delivered via a backdoored build of NetSarang's server management software in a supply-chain compromise.
  • Positive Technologies first documents the Space Pirates threat actor's exclusive use of Deed RAT, the direct code-lineage predecessor of BLOODALCHEMY (year-level precision only; exact date not given in source material).
  • Positive Technologies publishes a detailed report on Space Pirates' Deed RAT operations against Russian and Serbian government, education, aerospace, defense, energy, and healthcare organizations, including the related Voidoor and Portmap tools.
  • The Hacker News reports on Positive Technologies' Space Pirates/Deed RAT findings.
  • Elastic Security Labs first names and discloses the BLOODALCHEMY backdoor as part of the China-nexus REF5961 intrusion set targeting an ASEAN Ministry of Foreign Affairs, publishing sample hashes and the BrDifxapi.exe/BrLogAPI.dll DLL side-loading chain.
  • The Register covers Elastic's BLOODALCHEMY/REF5961 disclosure.
  • ITOCHU Cyber & Intelligence publishes code-level analysis tracing BLOODALCHEMY's lineage through Deed RAT to ShadowPad, detailing the VPN-maintenance-account-compromise infection vector, the DIFX shellcode container, 7 run modes, 15 backdoor commands, and QueueUserAPC-based process injection.
  • The Hacker News covers ITOCHU's lineage findings and connects the shared tooling to the February 2024 I-Soon leak's revelation of centralized 'digital quartermaster' hack-for-hire tool-sharing among Chinese threat clusters.

Sources cited for BloodAlchemy RAT Traced to Deed RAT/ShadowPad Lineage via

Detection coverage for TL-2026-2426

As of 2026-09-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2426 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
20 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats