PingPull

MITRE ATT&CK: S1031 View on attack.mitre.org

Aliases: PingPull

First seen
2022-06-01 00:00:00
Malware type
rat
Family
Malware family
Operating systems
windows
Related IoCs
2 (2 malicious)
Last IoC activity
2026-08-08 14:18:28
Profile updated
2026-07-07 13:08:16

Targeted industries: technology-and-telecommunications financial-services government-and-public-sector

Targeted regions: country_code:af country_code:au country_code:be country_code:kh country_code:my country_code:mz country_code:ph country_code:ru country_code:vn

Context

PingPull is a remote access Trojan (RAT) written in Visual C++ that has been used by GALLIUM since at least June 2022. PingPull has been used to target telecommunications companies, financial institutions, and government entities in Afghanistan, Australia, Belgium, Cambodia, Malaysia, Mozambique, the Philippines, Russia, and Vietnam.

Recent IoC activity

2 malicious indicators in Maltiverse are attributed to PingPull (S1031). The 2 most recently updated:

TypeIndicatorUpdatedSources
file sample ubuntu.trusty.tar.xz 2026-08-08 1
file sample cb0922d8b130504bf9a3078743294791201789c5a3d7bc0369afd096ea15f0ae.7z 2026-06-18 1

Detection coverage

  • 2 YARA rules
  • 204 Sigma rules

Malware & tools used

  • Non-Standard Port (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Data from Local System (attack-pattern)
  • Web Protocols (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Masquerade Task or Service (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Standard Encoding (attack-pattern)
  • Windows Service (attack-pattern)
  • Timestomp (attack-pattern)
  • Non-Application Layer Protocol (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Symmetric Cryptography (attack-pattern)

Used by threat actors

Detection rules

  • SEKOIA_Implant_Win_Pingpull (yara-rule)
  • SEKOIA_Apt_Granitetyphoon_Pingpulllinux_Strings (yara-rule)

Reports & references

  • blog.sekoia.io — My Teas Not Cold An Overview Of China Cyber Threat (report)
  • Palo Alto Unit 42 — Pingpull Gallium (report)
  • malpedia.caad.fkie.fraunhofer.de — Elf.Pingpull (report)
  • Palo Alto Unit 42 — Alloy Taurus (report)
  • MITRE ATT&CK — S1031 (report)

External references