PITSOCK
- Malware type
- backdoor
- Last IoC activity
- 2026-07-10 14:43:22
- Profile updated
- 2026-07-07 14:23:22
Context
According to Mandiant, this is backdoor which hooks the accept and setsockopt of the web process by modifying its procedure linkage table (PLT). This enables backdoor communication via the Unix socket /tmp/clientsDownload.sock when it receives a specific 48-byte magic byte sequence in the incoming buffer.
Reports & references
- cloud.google.com — Investigating Ivanti Exploitation Persistence (report)
- malpedia.caad.fkie.fraunhofer.de — Elf.Pitsock (report)