DRIFTPIN

Aliases: Spy.Agent.ORM, Toshliph

First seen
2013-04-23 00:00:00
Malware type
backdoor, rat, screen-capture
Family
Malware family
Profile updated
2026-07-07 12:45:32

Targeted industries: government-and-public-sector defense-and-aerospace

Context

Driftpin is a small and simple backdoor that enables the attackers to assess the victim. When executed the trojan connects to a C&C server and receives commands to grab screenshots, enumerate running processes and get information about the system and campaign ID.

Reports & references

  • secureworks.com — Gold Niagara (report)
  • Mandiant — Behind The Carbanak Backdoor (report)
  • cert.ssi.gouv.fr — 20220427 Np Tlpwhite Anssi Fin7 (report)
  • Mandiant — Cds18 Technical S05 Att&Cking Fin7 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Driftpin (report)
  • ESET — Carbanak Gang Is Back And Packing New Guns (report)

External references