PITSTOP

MITRE ATT&CK: S1123 View on attack.mitre.org

Aliases: PITSTOP

First seen
2021-06-21 00:00:00
Malware type
backdoor
Family
Malware family
Operating systems
network-devices
Related IoCs
2
Last IoC activity
2026-09-01 15:01:43
Profile updated
2026-07-07 13:13:11

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

PITSTOP is a backdoor that was deployed on compromised Ivanti Connect Secure VPNs during Cutting Edge to enable command execution and file read/write.

Detection coverage

  • 29 Sigma rules

Malware & tools used

  • Asymmetric Cryptography (attack-pattern)
  • Inter-Process Communication (attack-pattern)
  • Unix Shell (attack-pattern)
  • Socket Filters (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)

Used by threat actors

  • Cutting Edge (campaign)

Reports & references

  • Mandiant — Investigating Ivanti Exploitation Persistence (report)
  • MITRE ATT&CK — S1123 (report)

External references