ETDA สำนักงานพัฒนาธุรกรรมทางอิเล็กทรอนิกส์
Electronic Transactions Development Agency
Report
Search
Home > List all groups > List all tools > List all groups using tool TESDAT

Threat Group Cards: A Threat Actor Encyclopedia

Permanent link Tool: TESDAT

NamesTESDAT
CategoryMalware
TypeLoader
Description(Trend Micro) The newer loader we later found is called TESDAT. It always loads a payload file with a “.dat” extension (like “mns.dat”). Instead of using common APIs like CreateThread to execute the decoded shellcode, it always calls an API called “SwitchToFiber,” which we think is an attempt to avoid detection. Our analysis showed two variants for TESDAT loaders. It can be either an EXE file or a DLL file with an export function called “Init.”
Information<https://www.trendmicro.com/en_us/research/25/d/earth-kurma-apt-campaign.html>

Last change to this tool card: 27 June 2025

Download this tool card in JSON format

All groups using tool TESDAT

ChangedNameCountryObserved

APT groups

XEarth KurmaChina2020 

1 group listed (1 APT, 0 other, 0 unknown)

Digital Service Security Center
Electronic Transactions Development Agency

Follow us on

Facebook Twitter

Report incidents

Telephone +66 (0)2-123-1227
E-mail [email protected]