Pupy

MITRE ATT&CK: S0192 View on attack.mitre.org

Aliases: Pupy

Malware type
rat
Family
Malware family
Operating systems
linux, windows, macos, android
Related IoCs
180 (16 malicious)
Last IoC activity
2026-09-02 00:39:45
Profile updated
2026-07-07 15:46:11

Context

Pupy is an open source, cross-platform (Windows, Linux, OSX, Android) remote administration and post-exploitation tool. It is written in Python and can be generated as a payload in several different ways (Windows exe, Python file, PowerShell oneliner/file, Linux elf, APK, Rubber Ducky, etc.). Pupy is publicly available on GitHub.

Recent IoC activity

17 malicious indicators in Maltiverse are attributed to Pupy (S0192). The 17 most recently updated:

TypeIndicatorUpdatedSources
IP address 167.17.47.69 2026-09-02 1
hostname j2update.cc 2026-09-02 1
IP address 52.221.246.243 2026-08-28 1
IP address 38.147.188.28 2026-08-26 3
IP address 104.194.152.141 2026-08-17 4
IP address 154.40.62.125 2026-08-11 1
IP address 45.140.204.12 2026-08-09 4
file sample ab8e333ef9bc5c5a7d1ed4cab08335861e150b0639d3d0ca4c30b7def5cdccde 2026-04-08 1
file sample ad186df91282cf78394ef3bd60f04d859bcacccbcdcbfb620cc73f19ec0cec64 2026-04-03 1
file sample 6c8f413111f1abfee788dad4ee7cca37e0c2597cca66d155af958c535faf55cc 2026-04-01 1
file sample 0375f4b3fe011b35e6575133539441009d015ebecbee78b578c3ed04e0f22568 2026-03-31 1
file sample tmp2pucppke 2025-10-01 2
hostname nsdps.cc 2025-08-17 1
hostname maxpatrol.net 2025-04-29 1
hostname rcmsf100.net 2025-04-29 1
hostname ads-tm-glb.click 2025-04-29 2
hostname cbox4.ignorelist.com 2025-04-29 2

Detection coverage

  • 784 Sigma rules

Malware & tools used

  • Screen Capture (attack-pattern)
  • Credentials In Files (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Network Share Discovery (attack-pattern)
  • Asymmetric Cryptography (attack-pattern)
  • Bypass User Account Control (attack-pattern)
  • PowerShell (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • Domain Account (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Credentials from Web Browsers (attack-pattern)
  • Audio Capture (attack-pattern)
  • Dynamic-link Library Injection (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Local Email Collection (attack-pattern)
  • Systemd Service (attack-pattern)
  • Local Account (attack-pattern)
  • XDG Autostart Entries (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • System Information Discovery (attack-pattern)
  • LSASS Memory (attack-pattern)
  • Keylogging (attack-pattern)
  • Web Protocols (attack-pattern)
  • System Checks (attack-pattern)
  • Remote Desktop Protocol (attack-pattern)

Used by threat actors

Reports & references

  • github.com — Pupy (report)
  • MITRE ATT&CK — S0192 (report)

External references