Pupy
MITRE ATT&CK: S0192 View on attack.mitre.org
Aliases: Pupy
- Malware type
- rat
- Family
- Malware family
- Operating systems
- linux, windows, macos, android
- Related IoCs
- 180 (16 malicious)
- Last IoC activity
- 2026-09-02 00:39:45
- Profile updated
- 2026-07-07 15:46:11
Context
Pupy is an open source, cross-platform (Windows, Linux, OSX, Android) remote administration and post-exploitation tool. It is written in Python and can be generated as a payload in several different ways (Windows exe, Python file, PowerShell oneliner/file, Linux elf, APK, Rubber Ducky, etc.). Pupy is publicly available on GitHub.
Recent IoC activity
17 malicious indicators in Maltiverse are attributed to Pupy (S0192). The 17 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| IP address | 167.17.47.69 | 2026-09-02 | 1 |
| hostname | j2update.cc | 2026-09-02 | 1 |
| IP address | 52.221.246.243 | 2026-08-28 | 1 |
| IP address | 38.147.188.28 | 2026-08-26 | 3 |
| IP address | 104.194.152.141 | 2026-08-17 | 4 |
| IP address | 154.40.62.125 | 2026-08-11 | 1 |
| IP address | 45.140.204.12 | 2026-08-09 | 4 |
| file sample | ab8e333ef9bc5c5a7d1ed4cab08335861e150b0639d3d0ca4c30b7def5cdccde | 2026-04-08 | 1 |
| file sample | ad186df91282cf78394ef3bd60f04d859bcacccbcdcbfb620cc73f19ec0cec64 | 2026-04-03 | 1 |
| file sample | 6c8f413111f1abfee788dad4ee7cca37e0c2597cca66d155af958c535faf55cc | 2026-04-01 | 1 |
| file sample | 0375f4b3fe011b35e6575133539441009d015ebecbee78b578c3ed04e0f22568 | 2026-03-31 | 1 |
| file sample | tmp2pucppke | 2025-10-01 | 2 |
| hostname | nsdps.cc | 2025-08-17 | 1 |
| hostname | maxpatrol.net | 2025-04-29 | 1 |
| hostname | rcmsf100.net | 2025-04-29 | 1 |
| hostname | ads-tm-glb.click | 2025-04-29 | 2 |
| hostname | cbox4.ignorelist.com | 2025-04-29 | 2 |
Detection coverage
- 784 Sigma rules
Malware & tools used
- Screen Capture (attack-pattern)
- Credentials In Files (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Network Share Discovery (attack-pattern)
- Asymmetric Cryptography (attack-pattern)
- Bypass User Account Control (attack-pattern)
- PowerShell (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- Domain Account (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Credentials from Web Browsers (attack-pattern)
- Audio Capture (attack-pattern)
- Dynamic-link Library Injection (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Local Email Collection (attack-pattern)
- Systemd Service (attack-pattern)
- Local Account (attack-pattern)
- XDG Autostart Entries (attack-pattern)
- File and Directory Discovery (attack-pattern)
- System Information Discovery (attack-pattern)
- LSASS Memory (attack-pattern)
- Keylogging (attack-pattern)
- Web Protocols (attack-pattern)
- System Checks (attack-pattern)
- Remote Desktop Protocol (attack-pattern)
Used by threat actors
- Magic Hound (threat-actor)
- APT33 (threat-actor)
Reports & references
- github.com — Pupy (report)
- MITRE ATT&CK — S0192 (report)