Pierogi is a Windows backdoor used in politically motivated cyber-espionage operations targeting Palestinian individuals and entities, including victims likely connected to Palestinian government and political organizations. It was first publicly documented in campaigns active from late 2019 and has been linked by multiple researchers to the Gaza Cybergang ecosystem, including MoleRATs and later Arid Viper/APT-C-23 reporting, based on overlaps in victimology, lure themes, infrastructure patterns, and malware lineage.
Pierogi has typically been delivered through social-engineering lures centered on regional political affairs. Observed infection chains used executables masquerading as Microsoft Word documents as well as weaponized Office documents with downloader macros. The lures commonly referenced Palestinian politics, Hamas-Fatah tensions, government affairs, and other sensitive Middle East topics, indicating an espionage objective focused on intelligence collection.
The malware is a Delphi-based backdoor. Reported capabilities include host reconnaissance, screenshot capture, file upload, download of additional payloads, and remote command execution through the Windows command shell. It also queries Windows security product information via WMI to identify installed antivirus software. Persistence has been established through the Windows Startup folder. Reporting has also noted Ukrainian-language strings and command names in the malware, suggesting the code may have originated from or been influenced by Ukrainian-speaking developers rather than being wholly developed in-house by the operator.
Pierogi is associated with broader Gaza Cybergang tooling and campaigns that have also used families such as Spark, SharpStage, DropBook, Quasar RAT, and Micropsia-related malware. Later reporting assessed Pierogi++ as an evolution of the original Pierogi strain, sharing code and core backdoor functionality while continuing to target Palestinian entities. Across reporting, Pierogi is consistently characterized as an espionage implant used in targeted operations rather than indiscriminate crimeware.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
New Pierogi Variant: Hashes (SHA-256 + SHA-1) ... Domains judystevenson[.]info angeladeloney[.]info ruthgreenrtg[.]live escanor[.]live
We assess that Pierogi++ is based on an older malware strain named Pierogi, first observed in 2019.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
Pierogi++ samples implement in the same order the same backdoor functionalities as Pierogi: taking screenshots, command execution, and downloading attacker-provided files.
Some Primewire samples utilize “multipart/form-data” for command and control check-ins... other samples combine the C2 parameters into a single “application/x-www-form-urlencoded” POST body.
The backdoor has rather basic C2 functionality implemented through a predefined set of URLs.
31 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An older backdoor strain implemented in Delphi and Pascal, sharing code, strings, reconnaissance techniques, and decoy-document deployment behavior with Pierogi++. It supports screenshots, command execution, and file download, and was later associated with Arid Viper infrastructure and operations.
A malware/tool observed in Gaza Cybergang operations supporting espionage objectives.
Previously undocumented Delphi backdoor used for cyber espionage. It collects system information, uploads files, downloads additional payloads, takes screenshots, executes arbitrary CMD shell commands, checks for installed security products, and persists via a startup-folder shortcut.
A backdoor previously reported by Cybereason as part of targeted attacks against Palestinian officials and attributed to Molerats.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.