pupy (Windows)
Aliases: Patpoopy
- Malware type
- rat
- Family
- Malware family
- Last IoC activity
- 2026-07-22 00:34:01
- Profile updated
- 2026-07-07 12:42:33
Context
Pupy is an open-source, cross-platform RAT and post-exploitation framework mainly written in python. Pupy can be loaded from various loaders, including PE EXE, reflective DLL, Linux ELF, pure python, powershell and APK. Most of the loaders bundle an embedded python runtime, python library modules in source/compiled/native forms as well as a flexible configuration. They bootstrap a python runtime environment mostly in-memory for the later stages of pupy to run in. Pupy can communicate using various transports, migrate into processes, load remote python code, python packages and python C-extensions from memory.
Reports & references
- Broadcom/Symantec — Elfin Apt33 Espionage (report)
- researchcenter.paloaltonetworks.com — Unit42 Magic Hound Campaign Attacks Saudi Targets (report)
- secureworks.com — Iranian Pupyrat Bites Middle Eastern Organizations (report)
- securityaffairs.co — Magic Hound Campaign (report)
- Trend Micro — Wp Operation Earth Berberoka (report)
- Trend Micro — Earth Berberoka Linux Iocs 2.Txt (report)
- volexity.com — Driftingcloud Zero Day Sophos Firewall Exploitation And An Insidious Breach (report)
- cyble.com — Analysing The Utg Q 010 Campaign (report)
- Broadcom/Symantec — Elfin Apt33 Espionage (report)
- Mandiant — Cds19 Executive S08 Achievement Unlocked (report)
- github.com — Pupy (report)
- go.recordedfuture.com — Cta 2020 0123 (report)
- Mandiant — Overruled Containing A Potentially Destructive Adversary (report)
- infinitumit.com.tr — Apt 35 (report)
- go.recordedfuture.com — Cta 2022 0330 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Pupy (report)
- blog.cyber4sight.com — Malicious Powershell Script Analysis Indicates Shamoon Actors Used Pupy Rat (report)
- labs.k7computing.com — Pupy Rat Hiding Under Werfaults Cover (report)