PyXie is a Windows remote access trojan associated with a financially motivated intrusion cluster active since at least 2018 and tracked under names including GOLD DUPONT and DefrayX. It has been used alongside the Vatet loader, Cobalt Strike, and Defray777/RansomExx ransomware in targeted enterprise intrusions affecting sectors such as healthcare, education, government, and technology. In observed operations, initial access has been obtained through malware such as IcedID or TrickBot, after which Vatet or other tooling loads PyXie for post-compromise activity before ransomware deployment.
PyXie is used primarily for reconnaissance, credential collection, and data theft. Reported functionality includes host and network discovery, software and process enumeration, collection of screenshots and system information, discovery of administrative groups and shared resources, and harvesting of credentials through modules and companion tools such as LaZagne and Mimikatz. A tailored variant known as PyXie Lite has been used to identify and stage files likely to be sensitive to the victim organization, including business documents, infrastructure-related files, remote access configurations, password stores, and cryptocurrency wallet data. PyXie Lite has also been observed performing service and port discovery across enterprise environments and preparing collected data for exfiltration.
Development and operational overlaps tie PyXie closely to Vatet and Defray777, including shared code characteristics and build artifacts. In intrusion chains attributed to the same operators, PyXie supports hands-on-keyboard post-exploitation and data theft that can precede extortion or ransomware execution. Its role in these campaigns makes it a key component of a broader financially motivated ecosystem focused on enterprise compromise, reconnaissance, exfiltration, and follow-on ransomware impact.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"305419896": "Ryuk/TrickBot/Maze/EvilCorp/Pyxie/APT41 - Stats uniques -> ips/hostnames: 344 publickeys: 200"
Next, the threat group uses a tailored version of PyXie, which we call PyXie Lite, to conduct reconnaissance and to find and exfiltrate files that are likely sensitive to the victim organization.
RansomExx is operated by the DefrayX threat actor group (Hive0091), which is also known for the PyXie malware, Vatet loader, and Defray ransomware strains.
Next, the threat group uses a tailored version of PyXie, which we call PyXie Lite, to conduct reconnaissance and to find and exfiltrate files that are likely sensitive to the victim organization.
RansomExx is operated by the DefrayX threat actor group (Hive0091), which is also known for the PyXie malware, Vatet loader, and Defray ransomware strains.
"...SPRITE SPIDER likely used the PyXie remote access trojan (RAT) LaZagne module to harvest vCenter administrator credentials..."
7 distinct techniques documented for this family, organized by ATT&CK tactic.
46 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Write-up about PyXie >> [[URL_77bebde3_63]]
Named as malware associated with the DefrayX group.
Post-intrusion information-gathering tool delivered via Vatet loader as part of the toolchain preceding RansomExx deployment.
Named malware family discussed as likely sharing a common developer/maintainer with Vatet and Defray777 (financially motivated).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.