Pyramid

First seen
2020-08-18 00:00:00
Malware type
rat
Last IoC activity
2026-07-18 22:19:20
Profile updated
2026-07-07 14:33:43

Targeted industries: government-and-public-sector technology-and-telecommunications financial-services

Context

According to its author, Pyramid is a post exploitation framework written in Python, capable of executing offensive tooling from a signed binary (e.g. python.exe) by importing their dependencies in memory. It was created to demonstrate a bypass strategy against EDRs based on some blind-spots assumptions.

Reports & references

  • thedfirreport.com — The Curious Case Of An Egg Cellent Resume (report)
  • malpedia.caad.fkie.fraunhofer.de — Py.Pyramid (report)
  • github.com — Pyramid (report)
  • hunt.io — Tracking Pyramid C2 Identifying Post Exploitation Servers (report)
  • hunt.io — Russian Speaking Actors Impersonate Etf Distribute Stealc Pyramid C2 (report)
  • hunt.io — Russian Actor Cloudflare Phishing Telegram C2 (report)

External references