PITHOOK
- First seen
- 2023-08-15 00:00:00
- Malware type
- trojan, webshell
- Last IoC activity
- 2026-07-10 14:43:19
- Profile updated
- 2026-07-07 14:23:16
Targeted industries: technology-and-telecommunications government-and-public-sector
Context
According to Mandiant, PITHOOK hooks the accept and accept4 functions within the web process by modifying the PLT. When PITHOOK receives a buffer matching the predefined magic byte sequence, it will duplicate the socket and forward it to PITSTOP over the Unix domain socket /data/runtime/cockpit/wd.fd.
Reports & references
- cloud.google.com — Investigating Ivanti Exploitation Persistence (report)
- malpedia.caad.fkie.fraunhofer.de — Elf.Pithook (report)