Ping
MITRE ATT&CK: S0097 View on attack.mitre.org
Aliases: Ping
- Last IoC activity
- 2026-07-20 11:58:48
- Profile updated
- 2026-07-07 15:32:42
Context
Ping is an operating system utility commonly used to troubleshoot and verify network connections.
Detection coverage
- 16 Sigma rules
Malware & tools used
- Remote System Discovery (attack-pattern)
Used by threat actors
- Operation Digital Eye (campaign)
- C0018 (campaign)
- 2025 Poland Wiper Attacks (campaign)
- C0017 (campaign)
- Gamaredon Group (threat-actor)
- Magic Hound (threat-actor)
- Volt Typhoon (threat-actor)
- FIN8 (threat-actor)
- Naikon (threat-actor)
- GALLIUM (threat-actor)
- menuPass (threat-actor)
- ToddyCat (threat-actor)
- Ke3chang (threat-actor)
- HEXANE (threat-actor)
- APT41 (threat-actor)
- Lotus Blossom (threat-actor)
- Deep Panda (threat-actor)
- Wizard Spider (threat-actor)
- MirrorFace (threat-actor)
Reports & references
- MITRE ATT&CK — S0097 (report)
- Microsoft — Bb490968 (report)