PipeSnoop

Aliases: TOFUPIPE

First seen
2023-07-15 00:00:00
Malware type
rat
Family
Malware family
Profile updated
2026-07-07 13:07:38

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

Cisco Talos states that PipeSnoop can accept arbitrary shellcode from a named pipe and execute it on the infected endpoint.

Reports & references

  • Cisco Talos — Introducing Shrouded Snooper (report)
  • cloud.google.com — Unc1860 Iran Middle Eastern Networks (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Pipesnoop (report)

External references