Pirpi, also known as SHOTPUT and Backdoor.APT.CookieCutter, is a Windows remote access Trojan and DLL-based backdoor used by the China-based cyberespionage group APT3, also tracked as Gothic Panda, Buckeye, and UPS Team. It has been deployed against organizations in the United States and United Kingdom, with associated campaigns targeting aerospace, defense, energy, telecommunications, technology, transportation, and manufacturing.
Pirpi supports remote command execution, file uploads and downloads, process management, and system-information collection. Its discovery commands enumerate running processes, connected users, domain servers, and domain controllers. It also uses netstat to retrieve TCP connection status and supports file and directory discovery. These functions enable reconnaissance and operator-controlled post-exploitation activity on compromised systems.
Pirpi communicates with command-and-control servers using HTTP GET requests, placing encrypted data in Cookie headers and extracting encoded commands from HTML tags in server responses. Some variants support SSL and contain embedded cryptographic keys. Observed versions employ anti-disassembly techniques and delayed execution; later variants add randomized sleep behavior and more complex encoding to hinder sandboxing and debugging.
Delivery has included malicious links and attachments in spearphishing campaigns and exploitation of Internet Explorer and Adobe Flash vulnerabilities, including CVE-2010-3962, CVE-2014-1776, CVE-2015-3113, and CVE-2015-5119. In several exploit chains, encrypted Pirpi payloads were concealed within animated GIF images using steganography before being decoded and executed.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
the most recent original zero-day released by this group is tracked by CVE-2015-3113, which has similarities to the once zero-day vulnerabilities CVE-2014-1776 and CVE-2014-6332 exploited by UPS in May and November 2014, respectively. | UPS has relied on steganography to conceal the payloads delivered after exploitation of zero-days by embedding payloads, specifically the Pirpi backdoor within animated GIFs.
Unit 42 recently analyzed malicious Flash files that exploited CVE-2015-3113, which was a zero-day vulnerability in Adobe Flash that was patched on June 23, 2015. | UPS has relied on steganography to conceal the payloads delivered after exploitation of zero-days by embedding payloads, specifically the Pirpi backdoor within animated GIFs.
the most recent original zero-day released by this group is tracked by CVE-2015-3113, which has similarities to the once zero-day vulnerabilities CVE-2014-1776 and CVE-2014-6332 exploited by UPS in May and November 2014, respectively. | UPS has relied on steganography to conceal the payloads delivered after exploitation of zero-days by embedding payloads, specifically the Pirpi backdoor within animated GIFs.
They have a number of backdoors including one known as Pirpi... CVE-2010-3962, then a 0-day exploit in Internet Explorer 6, 7, and 8 dropped the Pirpi payload...
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
FireEye researchers analysing the Pirpi backdoor used by APT3 identified a sample that communicated with the domain twadcorp[.]com.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
Third, both shellcodes have similar single byte XOR algorithms used to decrypt and later execute the functional payload.
The malware author used steganography to embed an encrypted payload within this animated GIF image. The payload in the CVE-2014-1776 was also embedded within an animated GIF.
JPIN uses a encrypted and compressed payload that is disguised as a bitmap within the resource section of the installer. Ramsay has base64-encoded its portable executable and hidden itself under a JPG header. TEARDROP created and read from a file with a fake JPG header.
9 Load a DLL from %APPDATA% and execute one of its exported functions
APT3 has a tool that can detect the existence of remote systems.
APT3 has a tool that can enumerate current network connections.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content is a long ATT&CK-style listing of groups and malware that can 'list files and directories,' 'search for files,' 'enumerate drives,' 'gather file metadata,' or 'browse file systems' on compromised hosts.
APT3 has used a tool that can obtain info about local and global group users, power users, and administrators.
FIN8 has used dsquery and other Active Directory utilities to enumerate hosts; they have also used nltest.exe /dclist to retrieve a list of domain controllers.
FireEye researchers analysing the Pirpi backdoor used by APT3 identified a sample that communicated with the domain twadcorp[.]com.
17 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Provides commands to list domain servers and locate domain controllers.
Backdoor malware with a command to obtain a process listing.
Provides commands to enumerate domain servers and locate domain controllers.
A backdoor with commands to enumerate domain servers and locate domain controllers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.