SHOTPUT
MITRE ATT&CK: S0063 View on attack.mitre.org
Aliases: Backdoor.APT.CookieCutter, Pirpi, CookieCutter, SHOTPUT
- First seen
- 2015-05-01 00:00:00
- Malware type
- backdoor
- Family
- Malware family
- Operating systems
- windows
- Last IoC activity
- 2026-04-23 03:05:10
- Profile updated
- 2026-07-07 12:35:27
Targeted industries: government-and-public-sector financial-services technology-and-telecommunications
Targeted regions: country_code:us country_code:hk
Context
SHOTPUT is a custom backdoor linked to APT3, known for conducting cyber espionage activities. It enables remote access and control over compromised systems, often targeting government and financial sectors.
Detection coverage
- 1 YARA rules
- 150 Sigma rules
Malware & tools used
- Obfuscated Files or Information (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Local Account (attack-pattern)
- Remote System Discovery (attack-pattern)
- System Network Connections Discovery (attack-pattern)
- Process Discovery (attack-pattern)
Used by threat actors
- APT3 (threat-actor)
Exploited vulnerabilities
- CVE-2015-3113 (vulnerability)
Detection rules
- MALPEDIA_Win_Pirpi_Auto (yara-rule)
Reports & references
- Mandiant — Operation Clandestine Wolf Adobe Flash Zero Day (report)
- web.archive.org — Buckeye Cyberespionage Group Shifts Gaze Us Hong Kong (report)
- secureworks.com — Bronze Mayfair (report)
- Mandiant — Operation Doubletap (report)
- web.archive.org — Globalthreatintelreport (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Pirpi (report)
- researchcenter.paloaltonetworks.com — Ups Observations On Cve 2015 3113 Prior Zero Days And The Pirpi Payload (report)
- Mandiant — Clandestine Fox Part Deux (report)
- MITRE ATT&CK — S0063 (report)