PingPull
MITRE ATT&CK: S1031 View on attack.mitre.org
Aliases: PingPull
- First seen
- 2022-06-01 00:00:00
- Malware type
- rat
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 2 (2 malicious)
- Last IoC activity
- 2026-08-08 14:18:28
- Profile updated
- 2026-07-07 13:08:16
Targeted industries: technology-and-telecommunications financial-services government-and-public-sector
Targeted regions: country_code:af country_code:au country_code:be country_code:kh country_code:my country_code:mz country_code:ph country_code:ru country_code:vn
Context
PingPull is a remote access Trojan (RAT) written in Visual C++ that has been used by GALLIUM since at least June 2022. PingPull has been used to target telecommunications companies, financial institutions, and government entities in Afghanistan, Australia, Belgium, Cambodia, Malaysia, Mozambique, the Philippines, Russia, and Vietnam.
Recent IoC activity
2 malicious indicators in Maltiverse are attributed to PingPull (S1031). The 2 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | ubuntu.trusty.tar.xz | 2026-08-08 | 1 |
| file sample | cb0922d8b130504bf9a3078743294791201789c5a3d7bc0369afd096ea15f0ae.7z | 2026-06-18 | 1 |
Detection coverage
- 2 YARA rules
- 204 Sigma rules
Malware & tools used
- Non-Standard Port (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Data from Local System (attack-pattern)
- Web Protocols (attack-pattern)
- System Information Discovery (attack-pattern)
- Masquerade Task or Service (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Standard Encoding (attack-pattern)
- Windows Service (attack-pattern)
- Timestomp (attack-pattern)
- Non-Application Layer Protocol (attack-pattern)
- Windows Command Shell (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Symmetric Cryptography (attack-pattern)
Used by threat actors
- GALLIUM (threat-actor)
Detection rules
- SEKOIA_Implant_Win_Pingpull (yara-rule)
- SEKOIA_Apt_Granitetyphoon_Pingpulllinux_Strings (yara-rule)
Reports & references
- blog.sekoia.io — My Teas Not Cold An Overview Of China Cyber Threat (report)
- Palo Alto Unit 42 — Pingpull Gallium (report)
- malpedia.caad.fkie.fraunhofer.de — Elf.Pingpull (report)
- Palo Alto Unit 42 — Alloy Taurus (report)
- MITRE ATT&CK — S1031 (report)