pupy (ELF)
- First seen
- 2015-06-01 00:00:00
- Malware type
- rat, loader
- Family
- Malware family
- Profile updated
- 2026-07-07 14:28:54
Targeted industries: government-and-public-sector technology-and-telecommunications
Context
Pupy is an open-source, cross-platform RAT and post-exploitation framework mainly written in python. Pupy can be loaded from various loaders, including PE EXE, reflective DLL, Linux ELF, pure python, powershell and APK. Most of the loaders bundle an embedded python runtime, python library modules in source/compiled/native forms as well as a flexible configuration. They bootstrap a python runtime environment mostly in-memory for the later stages of pupy to run in. Pupy can communicate using various transports, migrate into processes, load remote python code, python packages and python C-extensions from memory.
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Elf.Pupy (report)
- github.com — Pupy (report)
- go.recordedfuture.com — Cta 2020 0123 (report)