Threat reportMalwareTL-2026-2426
BloodAlchemy RAT Traced to Deed RAT/ShadowPad Lineage via VPN Account Compromise and DLL Side-Loading
BloodAlchemy RAT Traced to Deed RAT/ShadowPad Lineage via (TL-2026-2426), also tracked as BLOODALCHEMY, is a high-severity malware campaign, first published 2026-09-10. It is attributed to REF5961 (China) with medium confidence, affects Brother Industries BrDifxapi.exe (device driver installer utility), maps to 18 MITRE ATT&CK techniques (T1027, T1027.011, T1053.005), and is covered by 9 detection rules and 20 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 18MITRE ATT&CK
- Actors
- 1REF5961
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 20Indicators of compromise
Key facts for TL-2026-2426
- Threat ID
- TL-2026-2426
- Also known as
- BLOODALCHEMY
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- REF5961
- Attribution confidence
- MEDIUM
- Nation-state nexus
- China
- Motivation
- ESPIONAGE
- Target sectors
- government administration
- Target regions
- Southeast Asia, mongolia
- Detection rules
- 9
- Indicators of compromise
- 20
Malware and tooling in BloodAlchemy RAT Traced to Deed RAT/ShadowPad Lineage via
Malware and tooling: BloodAlchemy, PlugX, SNAPPYBEE, ShadowPad, ShadowPad (POISONPLUG.SHADOW), Voidoor, Acunetix, Portmap, ShadowPad
How BloodAlchemy RAT Traced to Deed RAT/ShadowPad Lineage via works
ITOCHU Cyber & Intelligence's code-level analysis of the BLOODALCHEMY backdoor (first named by Elastic Security Labs in October 2023 as part of the REF5961 intrusion set) traces it to Deed RAT, a backdoor exclusive to the Space Pirates actor, which in turn descends from ShadowPad and PlugX. Observed intrusions begin with a compromised VPN maintenance account and use DLL side-loading (BrDifxapi.exe loading BrLogAPI.dll) to run a fileless, AES/LZNT1-decrypted shellcode payload.
ITOCHU Cyber & Intelligence researchers (published 2024-05-23) analyzed BLOODALCHEMY, a Windows x86 remote access trojan first named by Elastic Security Labs in October 2023 as part of the China-nexus REF5961 intrusion set that targeted an ASEAN member state's Ministry of Foreign Affairs, with secondary targeting observed in Mongolia. ITOCHU's code-level analysis traced BLOODALCHEMY's lineage backward through Deed RAT -- a backdoor exclusively attributed to the Space Pirates threat actor and documented in depth by Positive Technologies -- to ShadowPad (aka POISONPLUG.SHADOW), itself the successor to PlugX/Korplug. The lineage is evidenced by near-identical custom (non-PE) payload header structures, matching plugin-ID/magic-number schemes, shared shellcode-loading routines, comparable exception-handling patterns immediately following the payload entry point, and reused hardcoded persistence directory/filenames ("Test") across BLOODALCHEMY and Deed RAT samples.
Observed intrusions begin with compromise of a victim's VPN maintenance/vendor-support account, giving the actor an initial foothold without exploiting any software vulnerability. From there, three files are dropped into C:\windows\: the legitimate but certificate-revoked Brother Industries utility BrDifxapi.exe, a malicious loader DLL (BrLogAPI.dll) that BrDifxapi.exe side-loads, and an AES-128-CBC-encrypted shellcode container named DIFX whose decryption key is the file's own first 16 bytes. BrLogAPI.dll decrypts DIFX, applies a custom FNV-1a-hash-based decryption pass, and LZNT1-decompresses the result via RtlDecompressBuffer to recover a non-standard, non-PE payload (magic number 45 AB 45 AB) that is mapped with VirtualAlloc and executed entirely in memory -- BLOODALCHEMY's payload never exists as a standalone file on disk. Persistence is established via a scheduled task at C:\Windows\System32\Tasks\Dell\BrDifxapi, a Windows service named "Test" (description "Digital Imaging System"), and/or a CurrentVersion\Run registry key, selectable through a persistence-mode flag in the malware's configuration.
BLOODALCHEMY implements 7 operational run modes (ranging from bare C2 beaconing to full persistence + injection + anti-analysis) and 15 backdoor commands covering configuration management, self-update of all three toolset components, uninstall, registry-resident payload storage, proxy configuration, and victim reconnaissance (CPU/OS/network). Code execution into legitimate host processes (SearchIndexer.exe, wininit.exe, taskhost.exe, svchost.exe, taskeng.exe) uses Early Bird APC-queue injection (WriteProcessMemory + QueueUserAPC + ResumeThread). A configuration flag optionally activates Trellix-sandbox-detection logic (process names, file artifacts, DNS results) before the implant fully activates. The malware's configuration supports up to 10 configurable C2 destinations across eight protocols (DNS, HTTP, HTTPS, MUX, UDP, SMB, SOCKS4/5, TCP), though the ITOCHU-analyzed sample used only one; configuration data is itself protected with a rotating single-byte XOR key.
ITOCHU's code lineage points to the same malware ecosystem behind Deed RAT/Space Pirates, while Elastic separately assesses REF5961 as a distinct but related China-nexus, espionage-motivated intrusion set with high confidence, based on tooling and infrastructure correlation with earlier REF2924 activity. Subsequent media coverage noted that the February 2024 leak of Chinese state contractor I-Soon's internal materials plausibly explains why these outwardly separate Chinese clusters (REF5961/BLOODALCHEMY and Space Pirates/Deed RAT) share deeply similar tooling: the leak points to hack-for-hire "digital quartermaster" entities that build and distribute a shared malware toolkit across multiple state-directed campaigns rather than each actor independently engineering its own implants. No CVE is associated with this threat -- the abused weakness is a compromised third-party VPN maintenance credential, not a software vulnerability.
MITRE ATT&CK techniques used in TL-2026-2426
Defense Evasion
T1027 Obfuscated Files or Information; T1027.011 Obfuscated Files or Information: Fileless Storage; T1055.004 Process Injection: Asynchronous Procedure Call; T1140 Deobfuscate/Decode Files or Information; T1497 Virtualization/Sandbox Evasion; T1574.001 DLL
Persistence
T1053.005 Scheduled Task/Job: Scheduled Task; T1543.003 Create or Modify System Process: Windows Service; T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
Command and Control
T1071.001 Application Layer Protocol: Web Protocols; T1071.004 Application Layer Protocol: DNS; T1090 Proxy; T1095 Non-Application Layer Protocol
Initial Access
T1078 Valid Accounts; T1133 External Remote Services
Discovery
T1082 System Information Discovery
Execution
defense-impairment
Affected products and versions in BloodAlchemy RAT Traced to Deed RAT/ShadowPad Lineage via
- Brother Industries — BrDifxapi.exe (device driver installer utility)
Vulnerable versions: signed release with a since-revoked code-signing certificate, abused as a DLL side-loading host
Remediation for BloodAlchemy RAT Traced to Deed RAT/ShadowPad Lineage via
Immediate actions
- Audit and rotate credentials for all VPN maintenance/vendor-support accounts; enforce MFA on VPN administrative access
- Hunt for BrDifxapi.exe co-located with BrLogAPI.dll and a DIFX file outside expected Brother Industries install paths, especially under C:\windows\
- Alert on scheduled task creation under C:\Windows\System32\Tasks\Dell\BrDifxapi
- Alert on Windows service creation named "Test" with description "Digital Imaging System"
Workarounds
- Restrict execution of BrDifxapi.exe and other Brother Industries device-driver utilities to systems where legitimately required
- Network-segment VPN maintenance/vendor-access channels away from core infrastructure and monitor their authentication logs closely
Longer-term hardening
- Deploy EDR detection for QueueUserAPC/Early Bird APC-queue injection targeting SearchIndexer.exe, wininit.exe, taskhost.exe, svchost.exe, and taskeng.exe
- Implement application control / code-signing allowlisting to catch DLL side-loading via binaries with revoked or otherwise anomalous signatures
- Monitor for fileless shellcode execution patterns (VirtualAlloc following LZNT1 decompression via RtlDecompressBuffer)
- Baseline and alert on unexpected writes to CurrentVersion\Run and other registry-resident payload storage locations
Timeline of BloodAlchemy RAT Traced to Deed RAT/ShadowPad Lineage via
- ShadowPad, the earliest identifiable ancestor in BLOODALCHEMY's code lineage, is first identified after being delivered via a backdoored build of NetSarang's server management software in a supply-chain compromise.
- Positive Technologies first documents the Space Pirates threat actor's exclusive use of Deed RAT, the direct code-lineage predecessor of BLOODALCHEMY (year-level precision only; exact date not given in source material).
- Positive Technologies publishes a detailed report on Space Pirates' Deed RAT operations against Russian and Serbian government, education, aerospace, defense, energy, and healthcare organizations, including the related Voidoor and Portmap tools.
- The Hacker News reports on Positive Technologies' Space Pirates/Deed RAT findings.
- Elastic Security Labs first names and discloses the BLOODALCHEMY backdoor as part of the China-nexus REF5961 intrusion set targeting an ASEAN Ministry of Foreign Affairs, publishing sample hashes and the BrDifxapi.exe/BrLogAPI.dll DLL side-loading chain.
- The Register covers Elastic's BLOODALCHEMY/REF5961 disclosure.
- ITOCHU Cyber & Intelligence publishes code-level analysis tracing BLOODALCHEMY's lineage through Deed RAT to ShadowPad, detailing the VPN-maintenance-account-compromise infection vector, the DIFX shellcode container, 7 run modes, 15 backdoor commands, and QueueUserAPC-based process injection.
- The Hacker News covers ITOCHU's lineage findings and connects the shared tooling to the February 2024 I-Soon leak's revelation of centralized 'digital quartermaster' hack-for-hire tool-sharing among Chinese threat clusters.
Sources cited for BloodAlchemy RAT Traced to Deed RAT/ShadowPad Lineage via
- Malware Transmutation! - Unveiling the Hidden Traces of BloodAlchemy
- Disclosing the BLOODALCHEMY backdoor
- Introducing the REF5961 intrusion set
- Stealthy BLOODALCHEMY Malware Targeting ASEAN Government Networks
- Researchers Expose Space Pirates' Cyber Campaign Across Russia and Serbia
- Space Pirates: a look into the group's unconventional techniques, new attack vectors, and tools
- BLOODALCHEMY provides backdoor to ASEAN secrets
Detection coverage for TL-2026-2426
As of 2026-09-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2426 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.