PoisonIvy
MITRE ATT&CK: S0012 View on attack.mitre.org
Aliases: Breut, Poison Ivy, Darkmoon, SPIVY, pivy, poisonivy, PoisonIvy, Backdoor.Win32.PoisonIvy, Gen:Trojan.Heur.PT
- First seen
- 2005-01-01 00:00:00
- Malware type
- rat
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 21 (8 malicious)
- Last IoC activity
- 2026-08-15 16:03:25
- Profile updated
- 2026-07-07 15:45:46
Targeted industries: government-and-public-sector defense-and-aerospace financial-services technology-and-telecommunications
Context
PoisonIvy is a popular remote access tool (RAT) that has been used by many groups.
Recent IoC activity
8 malicious indicators in Maltiverse are attributed to PoisonIvy (S0012). The 8 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | vbs.vbs | 2026-08-15 | 1 |
| file sample | Lab03-01.exe | 2026-08-07 | 3 |
| file sample | 2026-08-06_6d222660187d1ee1bb6cf8cbfd0c3d9b_amadey_batrat_coinminer_elex_grap... | 2026-08-06 | 1 |
| file sample | 2026-06-03_c0b03c35dd79cc951342ef8d9b5fe6f4_amadey_batrat_coinminer_elex_nyma... | 2026-06-03 | 1 |
| file sample | 2026-06-02_4bcfd0f8fcf98b261d98a0e40d504148_amadey_batrat_coinminer_elex_grap... | 2026-06-02 | 1 |
| file sample | 2026-05-29_527e96547e39d087be776804c8e90236_amadey_batrat_coinminer_elex_nyma... | 2026-05-29 | 1 |
| file sample | 2026-05-04_1255cfdd42e25f0cdb0f3f60dd6686a7_elex_wannacry | 2026-05-04 | 1 |
| file sample | 44a7bea8a08f4c2feb74c6a00ff1114ba251f3dc6922ea5ffab9e749c98cbdce.exe | 2026-04-15 | 3 |
Detection coverage
- 1 YARA rules
- 359 Sigma rules
Malware & tools used
- Windows Service (attack-pattern)
- Modify Registry (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- Keylogging (attack-pattern)
- Active Setup (attack-pattern)
- Mutual Exclusion (attack-pattern)
- Dynamic-link Library Injection (attack-pattern)
- Local Data Staging (attack-pattern)
- Windows Command Shell (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Symmetric Cryptography (attack-pattern)
- Data from Local System (attack-pattern)
- Application Window Discovery (attack-pattern)
- Rootkit (attack-pattern)
Used by threat actors
- Operation Dust Storm (campaign)
- Tropic Trooper (threat-actor)
- Mustang Panda (threat-actor)
- APT1 (threat-actor)
- Axiom (threat-actor)
- Moafee (threat-actor)
- PittyTiger (threat-actor)
- Molerats (threat-actor)
- admin@338 (threat-actor)
- DragonOK (threat-actor)
- GALLIUM (threat-actor)
- menuPass (threat-actor)
- Elderwood (threat-actor)
- APT5 (threat-actor)
- IndigoZebra (threat-actor)
- APT14 (threat-actor)
Detection rules
- MALPEDIA_Win_Darkmoon_Auto (yara-rule)
Related threat objects
- Darkmoon (malware)
Reports & references
- paper.seebug.org — The Nitro Attacks (report)
- secureworks.com — Bronze Keystone (report)
- secureworks.com — Bronze Firestone (report)
- secureworks.com — Bronze Union (report)
- secureworks.com — Bronze Riverside (report)
- go.recordedfuture.com — Cta 2021 0616 (report)
- MITRE ATT&CK — G0011 (report)
- Palo Alto Unit 42 — Crawling Taurus (report)
- Mandiant — Know Your Enemy Tracking A Rapidly Evolving Apt Actor (report)
- Palo Alto Unit 42 — Shallowtaurus (report)
- Mandiant — Operation Molerats Middle East Cyber Attacks Using Poison Ivy (report)
- secureworks.com — Aluminum Saratoga (report)
- proofpoint.com — Chinese Apt Operation Lagtime It Targets Government Information Technology (report)
- recordedfuture.com — China Linked Ta428 Threat Group (report)
- youtube.com — Watch (report)
- vb2020.vblocalhost.com — Vb2020 20 (report)
- vb2020.vblocalhost.com — Vb2020 Ozawa Etal (report)
- cybereason.com — Operation Soft Cell A Worldwide Campaign Against Telecommunications Providers (report)
- Microsoft — Gallium Targeting Global Telecom (report)
- research.checkpoint.com — Vicious Panda The Covid Campaign (report)
- ESET — Operation Nightscout Supply Chain Attack Online Gaming Asia (report)
- virusbulletin.com — Vb2019 Paper Vine Climbing Over Great Firewall Longterm Attack Against China (report)
- researchcenter.paloaltonetworks.com — Unit42 Tropic Trooper Targets Taiwanese Government And Fossil Fuel Provider With Poison Ivy (report)
- web.archive.org — Executive Summary Final 1 (report)
- Mandiant — Rpt Poison Ivy (report)