PingPull is a remote access trojan associated with the Chinese espionage group GALLIUM, also tracked as Alloy Taurus and linked to Operation Soft Cell. It has been used in intrusions targeting telecommunications providers and later expanded to government and financial-sector organizations, including activity affecting Europe, Asia, and Africa. PingPull has been observed in both Windows and Linux variants, indicating ongoing development and cross-platform operational use.
The malware functions as a backdoor for remote command execution and host interaction. Reported capabilities include collecting data from compromised systems, exfiltrating stolen information over its command-and-control channel, modifying file timestamps for defense evasion, and installing itself as a service for persistence. Variants have used Base64 encoding in command-and-control traffic and have communicated over multiple protocols, including web-based channels as well as ICMP or TCP. Some variants have also used HTTPS on non-standard ports. Linux samples have been described as using AES-encrypted, Base64-encoded communications and supporting command sets for file operations, command execution, and timestomping.
PingPull is notable for being designed to blend into long-term espionage operations rather than disruptive activity. Its tradecraft aligns with persistent access, covert command-and-control, and data theft from strategically relevant networks. Public reporting has tied its use to campaigns focused on information theft and sustained access in sectors of geopolitical interest to Chinese state-linked operators.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Unit 42 researchers recently identified a new variant of PingPull malware used by Alloy Taurus actors designed to target Linux systems.
Unit 42 recently identified a new, difficult-to-detect remote access trojan named PingPull being used by GALLIUM, an advanced persistent threat (APT) group.
After a brief hiatus, the Alloy Taurus APT (aka Gallium or Operation Soft Cell) is back on the scene, with a new Linux variant of its PingPull malware.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
Many entries explicitly state malware 'can create a reverse shell' or 'launch a remote shell,' including 4H RAT, AuditCred, BLACKCOFFEE, Carbanak, DarkComet, Exaramel for Windows, PlugX, QuasarRAT, and ZxShell. | The content repeatedly describes use of cmd.exe, cmd /c, Windows command shell, and xp_cmdshell to execute commands, run payloads, launch binaries, perform reconnaissance, persistence, cleanup, and ransomware actions. Examples include: 'Sandworm Team used the xp_cmdshell command in MS-SQL', 'APT41 used cmd.exe /c to execute commands on remote machines', and many malware families 'can use cmd.exe to execute commands on a compromised host.'
The content repeatedly describes malware and threat actors using commands and APIs such as ipconfig /all, ifconfig, arp -a, route print, nbtstat, netsh, GetAdaptersInfo, and GetIpNetTable to gather IP addresses, MAC addresses, DNS, DHCP, gateways, routing tables, ARP cache, proxy settings, domains, and network adapter/interface details.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
It uses a statically linked OpenSSL (OpenSSL 0.9.8e) library to interact with the domain over HTTPS via the following HTTP POST request | Upon execution, this sample is configured to communicate with the domain yrhsywu2009.zapto[.]org over port 8443 for C2. It uses a statically linked OpenSSL (OpenSSL 0.9.8e) library to interact with the domain over HTTPS via the following HTTP POST request
"Anchor has used ICMP in C2 communications." / "COATHANGER uses ICMP for transmitting configuration information..." / "PHOREAL communicates via ICMP for C2." / "Regin ... can use ICMP to communicate between infected computers." / "Cobalt Strike can be configured to use TCP, ICMP, and UDP for C2 communications."
C2 traffic from ADVSTORESHELL is encrypted, then encoded with Base64 encoding... APT19 HTTP malware variant used Base64 to encode communications to the C2 server... APT33 has used base64 to encode command and control traffic.
4H RAT has the capability to create a remote shell. AuditCred can open a reverse shell on the system to execute commands. PlugX allows actors to spawn a reverse shell on a victim. QuasarRAT can launch a remote shell to execute commands on the victim’s machine.
ADVSTORESHELL exfiltrates data over the same channel used for C2... Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers... numerous malware and groups sent victim data, files, credentials, or host information over existing C2 channels.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor previously used by Gallium at the same target, cited here as attribution-supporting tooling connected to earlier activity.
Malware capable of timestomping files.
PingPull is a backdoor used by Gallium (Alloy Taurus) for remote access and espionage, with variants for Windows and Linux platforms.
A malware family used by the Alloy Taurus (Gallium / Operation Soft Cell) espionage actor; the content notes a retooled Linux variant, implying continued development and cross-platform capability for remote access/backdoor functionality.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.