Pyramid
- First seen
- 2020-08-18 00:00:00
- Malware type
- rat
- Last IoC activity
- 2026-07-18 22:19:20
- Profile updated
- 2026-07-07 14:33:43
Targeted industries: government-and-public-sector technology-and-telecommunications financial-services
Context
According to its author, Pyramid is a post exploitation framework written in Python, capable of executing offensive tooling from a signed binary (e.g. python.exe) by importing their dependencies in memory. It was created to demonstrate a bypass strategy against EDRs based on some blind-spots assumptions.
Reports & references
- thedfirreport.com — The Curious Case Of An Egg Cellent Resume (report)
- malpedia.caad.fkie.fraunhofer.de — Py.Pyramid (report)
- github.com — Pyramid (report)
- hunt.io — Tracking Pyramid C2 Identifying Post Exploitation Servers (report)
- hunt.io — Russian Speaking Actors Impersonate Etf Distribute Stealc Pyramid C2 (report)
- hunt.io — Russian Actor Cloudflare Phishing Telegram C2 (report)