Peppy is a Python-based remote access trojan associated with the Pakistan-linked threat cluster commonly tracked as Transparent Tribe, ProjectM, APT36, Mythic Leopard, and COPPER FIELDSTONE. It has been used in espionage operations primarily targeting Indian diplomatic, government, and military personnel, with reporting also indicating activity focused on Afghanistan. Peppy is part of a broader custom malware ecosystem that includes Crimson RAT and CapraRAT.
Documented Peppy capabilities include screenshot capture, keystroke logging, and automatic exfiltration of files and captured keylogs. These functions support intelligence collection from compromised hosts and align with the group’s long-running surveillance objectives. Peppy has been observed alongside other custom and commodity tooling in campaigns that used staged delivery chains to establish access and then deploy follow-on implants.
Observed delivery activity tied to the broader operator ecosystem includes spearphishing emails with malicious Office documents and macros, watering-hole activity, and use of the Andromeda malware as an initial payload to download and execute additional tools including Peppy. Peppy has been referenced as a custom RAT deployed by Transparent Tribe/COPPER FIELDSTONE in targeted intrusions against South Asian government and military-related victims.
Peppy is associated with Windows-focused intrusion activity, including campaigns that delivered Peppy to victim systems through document-based infection chains and downloader infrastructure. Its role within the operator toolkit is consistent with post-compromise surveillance and collection on infected endpoints.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
"...custom developed tools called Crimson and Peppy..." | "...spear-phishing emails with malicious RTF files exploiting CVE-2010-3333 or CVE-2012-0158..."
"...custom developed tools called Crimson and Peppy..." | "...spear-phishing emails with malicious RTF files exploiting CVE-2010-3333 or CVE-2012-0158..."
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"...custom developed tools called Crimson and Peppy..."
12 distinct techniques documented for this family, organized by ATT&CK tactic.
“…rely on both spear-phishing emails and watering hole sites… used a blog… ‘India News Tribe’ … as a watering hole to deliver their payloads.”
“The ProjectM actors rely on both spear-phishing emails and watering hole sites… ProjectM actors used… spear-phishing emails with malicious RTF files exploiting CVE-2010-3333 or CVE-2012-0158, in addition to Excel files that contained malicious macros…” | “…Excel files that contained malicious macros to download and install their payloads…”
Several entries refer generically to command-line interfaces, shell commands, scripting engines, or script execution without always specifying the exact interpreter.
Multiple entries describe identifying files for theft or staging, such as "Confucius has used a file stealer that checks the Document, Downloads, Desktop, and Picture folders for documents and images with specific extensions" and "Peppy can identify specific files for exfiltration."
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Enterprise New Software: ... Peppy
Backdoor malware capable of taking screenshots on targeted systems.
Python-based remote access trojan used by Transparent Tribe alongside Crimson tooling (no additional functional details provided in the content).
Custom Trojan used in the ProjectM toolset; delivered by Andromeda in this campaign and observed using ProjectM-controlled domains for C2.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.