# BloodAlchemy RAT Traced to Deed RAT/ShadowPad Lineage via VPN Account Compromise and DLL Side-Loading

> ITOCHU Cyber & Intelligence's code-level analysis of the BLOODALCHEMY backdoor (first named by Elastic Security Labs in October 2023 as part of the REF5961 intrusion set) traces it to Deed RAT, a backdoor exclusive to the Space Pirates actor, which in turn descends from ShadowPad and PlugX. Observed intrusions begin with a compromised VPN maintenance account and use DLL side-loading (BrDifxapi.exe loading BrLogAPI.dll) to run a fileless, AES/LZNT1-decrypted shellcode payload.

- **Published:** 2026-09-10T00:00:00Z
- **Last reviewed:** 2026-09-10T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2426
- **ID:** TL-2026-2426
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** REF5961 (China)
- **Detections:** 9 · **IOCs:** 20 (full data via the Threadlinqs MCP server — Purple tier)

## Description

ITOCHU Cyber & Intelligence researchers (published 2024-05-23) analyzed BLOODALCHEMY, a Windows x86 remote access trojan first named by Elastic Security Labs in October 2023 as part of the China-nexus REF5961 intrusion set that targeted an ASEAN member state's Ministry of Foreign Affairs, with secondary targeting observed in Mongolia. ITOCHU's code-level analysis traced BLOODALCHEMY's lineage backward through Deed RAT -- a backdoor exclusively attributed to the Space Pirates threat actor and documented in depth by Positive Technologies -- to ShadowPad (aka POISONPLUG.SHADOW), itself the successor to PlugX/Korplug. The lineage is evidenced by near-identical custom (non-PE) payload header structures, matching plugin-ID/magic-number schemes, shared shellcode-loading routines, comparable exception-handling patterns immediately following the payload entry point, and reused hardcoded persistence directory/filenames ("Test") across BLOODALCHEMY and Deed RAT samples.

Observed intrusions begin with compromise of a victim's VPN maintenance/vendor-support account, giving the actor an initial foothold without exploiting any software vulnerability. From there, three files are dropped into C:\windows\: the legitimate but certificate-revoked Brother Industries utility BrDifxapi.exe, a malicious loader DLL (BrLogAPI.dll) that BrDifxapi.exe side-loads, and an AES-128-CBC-encrypted shellcode container named DIFX whose decryption key is the file's own first 16 bytes. BrLogAPI.dll decrypts DIFX, applies a custom FNV-1a-hash-based decryption pass, and LZNT1-decompresses the result via RtlDecompressBuffer to recover a non-standard, non-PE payload (magic number 45 AB 45 AB) that is mapped with VirtualAlloc and executed entirely in memory -- BLOODALCHEMY's payload never exists as a standalone file on disk. Persistence is established via a scheduled task at C:\Windows\System32\Tasks\Dell\BrDifxapi, a Windows service named "Test" (description "Digital Imaging System"), and/or a CurrentVersion\Run registry key, selectable through a persistence-mode flag in the malware's configuration.

BLOODALCHEMY implements 7 operational run modes (ranging from bare C2 beaconing to full persistence + injection + anti-analysis) and 15 backdoor commands covering configuration management, self-update of all three toolset components, uninstall, registry-resident payload storage, proxy configuration, and victim reconnaissance (CPU/OS/network). Code execution into legitimate host processes (SearchIndexer.exe, wininit.exe, taskhost.exe, svchost.exe, taskeng.exe) uses Early Bird APC-queue injection (WriteProcessMemory + QueueUserAPC + ResumeThread). A configuration flag optionally activates Trellix-sandbox-detection logic (process names, file artifacts, DNS results) before the implant fully activates. The malware's configuration supports up to 10 configurable C2 destinations across eight protocols (DNS, HTTP, HTTPS, MUX, UDP, SMB, SOCKS4/5, TCP), though the ITOCHU-analyzed sample used only one; configuration data is itself protected with a rotating single-byte XOR key.

ITOCHU's code lineage points to the same malware ecosystem behind Deed RAT/Space Pirates, while Elastic separately assesses REF5961 as a distinct but related China-nexus, espionage-motivated intrusion set with high confidence, based on tooling and infrastructure correlation with earlier REF2924 activity. Subsequent media coverage noted that the February 2024 leak of Chinese state contractor I-Soon's internal materials plausibly explains why these outwardly separate Chinese clusters (REF5961/BLOODALCHEMY and Space Pirates/Deed RAT) share deeply similar tooling: the leak points to hack-for-hire "digital quartermaster" entities that build and distribute a shared malware toolkit across multiple state-directed campaigns rather than each actor independently engineering its own implants. No CVE is associated with this threat -- the abused weakness is a compromised third-party VPN maintenance credential, not a software vulnerability.

## MITRE ATT&CK

- T1133 External Remote Services
- T1078 Valid Accounts
- T1106 Native API
- T1055.004 Process Injection: Asynchronous Procedure Call
- T1053.005 Scheduled Task/Job: Scheduled Task
- T1543.003 Create or Modify System Process: Windows Service
- T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
- T1574.001 DLL
- T1027 Obfuscated Files or Information
- T1027.011 Obfuscated Files or Information: Fileless Storage
- T1140 Deobfuscate/Decode Files or Information
- T1497 Virtualization/Sandbox Evasion
- T1112 Modify Registry
- T1082 System Information Discovery
- T1071.001 Application Layer Protocol: Web Protocols
- T1071.004 Application Layer Protocol: DNS
- T1095 Non-Application Layer Protocol
- T1090 Proxy

## Sources

- [Malware Transmutation! - Unveiling the Hidden Traces of BloodAlchemy](https://blog-en.itochuci.co.jp/entry/2024/05/23/090000)
- [Disclosing the BLOODALCHEMY backdoor](https://www.elastic.co/security-labs/disclosing-the-bloodalchemy-backdoor)
- [Introducing the REF5961 intrusion set](https://www.elastic.co/security-labs/introducing-the-ref5961-intrusion-set)
- [Stealthy BLOODALCHEMY Malware Targeting ASEAN Government Networks](https://thehackernews.com/2024/05/japanese-experts-warn-of-bloodalchemy.html)
- [Researchers Expose Space Pirates' Cyber Campaign Across Russia and Serbia](https://thehackernews.com/2023/08/researchers-expose-space-pirate-cyber.html)
- [Space Pirates: a look into the group's unconventional techniques, new attack vectors, and tools](https://global.ptsecurity.com/en/research/pt-esc-threat-intelligence/space-pirates-a-look-into-the-group-s-unconventional-techniques-new-attack-vectors-and-tools/)
- [BLOODALCHEMY provides backdoor to ASEAN secrets](https://theregister.com/2023/10/16/bloodalchemy_backdoor)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2426
