PITSOCK

Malware type
backdoor
Last IoC activity
2026-07-10 14:43:22
Profile updated
2026-07-07 14:23:22

Context

According to Mandiant, this is backdoor which hooks the accept and setsockopt of the web process by modifying its procedure linkage table (PLT). This enables backdoor communication via the Unix socket /tmp/clientsDownload.sock when it receives a specific 48-byte magic byte sequence in the incoming buffer.

Reports & references

  • cloud.google.com — Investigating Ivanti Exploitation Persistence (report)
  • malpedia.caad.fkie.fraunhofer.de — Elf.Pitsock (report)

External references