Pupy RAT is an open-source, cross-platform remote access trojan used to provide attackers with interactive control over compromised systems. It is primarily associated with Windows intrusions in the supplied reporting, where it was deployed through DLL sideloading using the legitimate Windows Error Reporting binary WerFault.exe and a malicious faultrep.dll, with the payload decrypted and reflectively loaded into memory while a decoy document was opened to distract the victim. Pupy RAT supports in-memory execution and modular post-compromise activity, including remote command execution, data theft, downloading additional components, and broader post-exploitation actions that can facilitate lateral movement. The malware has been publicly available for years, which has made it attractive to both commodity operators and state-linked espionage actors. It has been linked in prior reporting to Iranian threat groups including APT33 and APT35, and it has also appeared in broader infrastructure tracking and DNS-tunneling-related investigations. In the observed campaign, delivery relied on a phishing lure carrying an ISO image and a shortcut that launched the sideload chain, indicating use in targeted intrusion activity against Windows users.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This blog describes how threat actors use the legitimate WerFault.exe to execute Pupy RAT on the victims’ machine.
This blog describes how threat actors use the legitimate WerFault.exe to execute Pupy RAT on the victims’ machine.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
The victim starts the infection chain by clicking on the shortcut file, which uses 'scriptrunner.exe' to execute WerFault.exe.
This PowerShell script, seen in Figure 5, appears to have been generated by Metasploit’s “web_delivery” module to download and execute a payload from a remote server at 45.76.128[.]71, which we speculate was used to create a meterpreter session on the system.
The ISO contains four files, a legitimate WerFault.exe, a malicious DLL named faultrep.dll, a shortcut file named recent inventory & our specialties.lnk and a XLS file named File.xls. The shortcut file has the same name as the ISO image.
This RAT is loaded into the memory and executed while WerFault.exe was executing in the front.
On further analysis we found the RC4 decryption function which contains the data and hard coded string as key... After decrypting the data, we confirmed that the data is a PE file with the magic bytes.
When the victim opens that shortcut file, it uses scriptrunner.exe LOLBin via cmd to execute WerFault.exe from the ISO.
В MITRE ATT&CK скрытые каналы покрывают сразу несколько тактик: Command and Control - DNS (T1071.004 ...). ... DNS tunneling (T1071.004, Command and Control ...) эксплуатирует штатный механизм рекурсивного разрешения имён.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan mentioned in relation to historical DNS tunneling lookups on infrastructure later used by the CapraRAT campaign; no clear campaign linkage established.
An open-source cross-platform remote access tool executed from memory via a side-loaded loader. In this case it was decrypted from overlay data using RC4, reflectively loaded, and attempted to establish C2 communications while masquerading behind WerFault.exe.
An open-source Python-based remote access trojan that supports reflective DLL loading to evade detection and can download additional modules. It gives attackers full access to infected devices, enabling command execution, data theft, further malware installation, and lateral movement.
Commodity RAT used by Elfin to establish backdoor access on compromised systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.