SHOTPUT, also known as Pirpi and Backdoor.APT.CookieCutter, is a Windows DLL backdoor associated with the Chinese espionage group APT3, also tracked as UPS Team, Gothic Panda, and Buckeye. It has been used in targeted intrusions against organizations including government, aerospace, defense, energy, telecommunications, transport, manufacturing, research, and political entities, with reporting tying its use to campaigns against victims in the United States, the United Kingdom, and Hong Kong.
SHOTPUT functions as a remote access backdoor that communicates over HTTP and has been described as capable of executing system commands, managing processes, transferring files, and collecting host information. Documented discovery functions include obtaining process listings, enumerating current TCP connection status via netstat, retrieving information about connected users, listing servers in a domain, and locating domain controllers. Related reporting on Pirpi variants also describes HTTP GET-based command-and-control patterns using encoded data in HTTP cookies, command retrieval from web content, optional SSL support in some variants, and anti-analysis measures such as delayed execution, anti-sandbox behavior, and obfuscation.
APT3 has delivered SHOTPUT and closely related Pirpi payloads through spearphishing emails containing malicious links or attachments, as well as through exploitation of browser and Flash zero-day vulnerabilities including CVE-2014-1776, CVE-2015-3113, and CVE-2015-5119. In some campaigns, payloads were concealed using steganography inside animated GIF files before extraction and execution. The malware has been used as part of methodical post-compromise operations focused on persistence, internal reconnaissance, lateral movement support, and theft of sensitive information.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
the most recent original zero-day released by this group is tracked by CVE-2015-3113, which has similarities to the once zero-day vulnerabilities CVE-2014-1776 and CVE-2014-6332 exploited by UPS in May and November 2014, respectively. | UPS has relied on steganography to conceal the payloads delivered after exploitation of zero-days by embedding payloads, specifically the Pirpi backdoor within animated GIFs.
Unit 42 recently analyzed malicious Flash files that exploited CVE-2015-3113, which was a zero-day vulnerability in Adobe Flash that was patched on June 23, 2015. | UPS has relied on steganography to conceal the payloads delivered after exploitation of zero-days by embedding payloads, specifically the Pirpi backdoor within animated GIFs.
the most recent original zero-day released by this group is tracked by CVE-2015-3113, which has similarities to the once zero-day vulnerabilities CVE-2014-1776 and CVE-2014-6332 exploited by UPS in May and November 2014, respectively. | UPS has relied on steganography to conceal the payloads delivered after exploitation of zero-days by embedding payloads, specifically the Pirpi backdoor within animated GIFs.
They have a number of backdoors including one known as Pirpi... CVE-2010-3962, then a 0-day exploit in Internet Explorer 6, 7, and 8 dropped the Pirpi payload...
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
FireEye researchers analysing the Pirpi backdoor used by APT3 identified a sample that communicated with the domain twadcorp[.]com.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
Third, both shellcodes have similar single byte XOR algorithms used to decrypt and later execute the functional payload.
The malware author used steganography to embed an encrypted payload within this animated GIF image. The payload in the CVE-2014-1776 was also embedded within an animated GIF.
JPIN uses a encrypted and compressed payload that is disguised as a bitmap within the resource section of the installer. Ramsay has base64-encoded its portable executable and hidden itself under a JPG header. TEARDROP created and read from a file with a fake JPG header.
9 Load a DLL from %APPDATA% and execute one of its exported functions
APT3 has a tool that can detect the existence of remote systems.
APT3 has a tool that can enumerate current network connections.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content is a long ATT&CK-style listing of groups and malware that can 'list files and directories,' 'search for files,' 'enumerate drives,' 'gather file metadata,' or 'browse file systems' on compromised hosts.
“actors used the following commands… to enumerate user accounts: net user >> %temp%\download; net user /domain >> %temp%\download … APT1 used the commands net localgroup, net user, and net group to find accounts… APT32 enumerated administrative users using the commands net localgroup administrators … OilRig has run net user, net user /domain, net group "domain admins" /domain …”
APT3 has used a tool that can obtain info about local and global group users, power users, and administrators.
FIN8 has used dsquery and other Active Directory utilities to enumerate hosts; they have also used nltest.exe /dclist to retrieve a list of domain controllers.
FireEye researchers analysing the Pirpi backdoor used by APT3 identified a sample that communicated with the domain twadcorp[.]com.
17 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor malware with a command to obtain a process listing.
A backdoor with commands to enumerate domain servers and locate domain controllers.
A backdoor used by APT3; the post discusses Pirpi samples communicating with attacker-controlled domains as part of tracing APT3 infrastructure and operators.
Pirpi is a remote access trojan used by APT3 to gain access to victim systems, typically delivered via malicious attachments or links in spear-phishing emails, and used in intrusions involving follow-on backdoor installation and theft of intellectual property or confidential information.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.