PITHOOK

First seen
2023-08-15 00:00:00
Malware type
trojan, webshell
Last IoC activity
2026-07-10 14:43:19
Profile updated
2026-07-07 14:23:16

Targeted industries: technology-and-telecommunications government-and-public-sector

Context

According to Mandiant, PITHOOK hooks the accept and accept4 functions within the web process by modifying the PLT. When PITHOOK receives a buffer matching the predefined magic byte sequence, it will duplicate the socket and forward it to PITSTOP over the Unix domain socket /data/runtime/cockpit/wd.fd.

Reports & references

  • cloud.google.com — Investigating Ivanti Exploitation Persistence (report)
  • malpedia.caad.fkie.fraunhofer.de — Elf.Pithook (report)

External references