DRIFTPIN
Aliases: Spy.Agent.ORM, Toshliph
- First seen
- 2013-04-23 00:00:00
- Malware type
- backdoor, rat, screen-capture
- Family
- Malware family
- Profile updated
- 2026-07-07 12:45:32
Targeted industries: government-and-public-sector defense-and-aerospace
Context
Driftpin is a small and simple backdoor that enables the attackers to assess the victim. When executed the trojan connects to a C&C server and receives commands to grab screenshots, enumerate running processes and get information about the system and campaign ID.
Reports & references
- secureworks.com — Gold Niagara (report)
- Mandiant — Behind The Carbanak Backdoor (report)
- cert.ssi.gouv.fr — 20220427 Np Tlpwhite Anssi Fin7 (report)
- Mandiant — Cds18 Technical S05 Att&Cking Fin7 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Driftpin (report)
- ESET — Carbanak Gang Is Back And Packing New Guns (report)