PoisonIvy

MITRE ATT&CK: S0012 View on attack.mitre.org

Aliases: Breut, Poison Ivy, Darkmoon, SPIVY, pivy, poisonivy, PoisonIvy, Backdoor.Win32.PoisonIvy, Gen:Trojan.Heur.PT

First seen
2005-01-01 00:00:00
Malware type
rat
Family
Malware family
Operating systems
windows
Related IoCs
21 (8 malicious)
Last IoC activity
2026-08-15 16:03:25
Profile updated
2026-07-07 15:45:46

Targeted industries: government-and-public-sector defense-and-aerospace financial-services technology-and-telecommunications

Context

PoisonIvy is a popular remote access tool (RAT) that has been used by many groups.

Recent IoC activity

8 malicious indicators in Maltiverse are attributed to PoisonIvy (S0012). The 8 most recently updated:

Detection coverage

  • 1 YARA rules
  • 359 Sigma rules

Malware & tools used

  • Windows Service (attack-pattern)
  • Modify Registry (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • Keylogging (attack-pattern)
  • Active Setup (attack-pattern)
  • Mutual Exclusion (attack-pattern)
  • Dynamic-link Library Injection (attack-pattern)
  • Local Data Staging (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Symmetric Cryptography (attack-pattern)
  • Data from Local System (attack-pattern)
  • Application Window Discovery (attack-pattern)
  • Rootkit (attack-pattern)

Used by threat actors

Detection rules

  • MALPEDIA_Win_Darkmoon_Auto (yara-rule)

Related threat objects

Reports & references

  • paper.seebug.org — The Nitro Attacks (report)
  • secureworks.com — Bronze Keystone (report)
  • secureworks.com — Bronze Firestone (report)
  • secureworks.com — Bronze Union (report)
  • secureworks.com — Bronze Riverside (report)
  • go.recordedfuture.com — Cta 2021 0616 (report)
  • MITRE ATT&CK — G0011 (report)
  • Palo Alto Unit 42 — Crawling Taurus (report)
  • Mandiant — Know Your Enemy Tracking A Rapidly Evolving Apt Actor (report)
  • Palo Alto Unit 42 — Shallowtaurus (report)
  • Mandiant — Operation Molerats Middle East Cyber Attacks Using Poison Ivy (report)
  • secureworks.com — Aluminum Saratoga (report)
  • proofpoint.com — Chinese Apt Operation Lagtime It Targets Government Information Technology (report)
  • recordedfuture.com — China Linked Ta428 Threat Group (report)
  • youtube.com — Watch (report)
  • vb2020.vblocalhost.com — Vb2020 20 (report)
  • vb2020.vblocalhost.com — Vb2020 Ozawa Etal (report)
  • cybereason.com — Operation Soft Cell A Worldwide Campaign Against Telecommunications Providers (report)
  • Microsoft — Gallium Targeting Global Telecom (report)
  • research.checkpoint.com — Vicious Panda The Covid Campaign (report)
  • ESET — Operation Nightscout Supply Chain Attack Online Gaming Asia (report)
  • virusbulletin.com — Vb2019 Paper Vine Climbing Over Great Firewall Longterm Attack Against China (report)
  • researchcenter.paloaltonetworks.com — Unit42 Tropic Trooper Targets Taiwanese Government And Fossil Fuel Provider With Poison Ivy (report)
  • web.archive.org — Executive Summary Final 1 (report)
  • Mandiant — Rpt Poison Ivy (report)

External references