PIEHOP

Malware type
trojan
Profile updated
2026-07-07 15:09:40

Targeted industries: energy-and-utilities

Context

According to Mandiant, PIEHOP is a disruption tool written in Python and packaged with PyInstaller version 2.1+ that has the capability to connect to a user supplied remote MSSQL server for uploading files and issuing remote commands to a RTU. PIEHOP expects its main function to be called via another Python file, supplying either the argument control=True or upload=True. At a minimum, it requires the following arguments: oik, user, and pwd, and if called with control=True, it must also be supplied with iec104.

Reports & references

  • Mandiant — Cosmicenergy Ot Malware Russian Response (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Piehop (report)

External references