Poison Ivy is a widely shared and long-established remote access trojan (RAT), first identified in 2005 and also referred to in the provided content as Breut and Darkmoon. It provides covert remote access and surveillance capabilities on compromised systems and is described as enabling attackers to control infected computers, collect data, and support broader post-compromise activity. The content notes Poison Ivy has been used for many years, including in notable incidents such as the 2011 RSA breach, where a customized reverse-connect Poison Ivy variant was installed after spear-phishing with an Excel attachment exploiting Adobe Flash vulnerability CVE-2011-0609. In other campaigns, Poison Ivy was delivered via spear-phishing and malicious documents, including Operation LagTime IT targeting East Asian government agencies with RTF files exploiting CVE-2018-0798, and earlier PKPLUG-related and Bookworm-linked activity using phishing and DLL side-loading packages.
Observed behaviors in the content include persistence through Windows Registry and service modification. Poison Ivy creates a Registry subkey that registers a new service, and also modifies the Logical Disk Manager service to point to a malicious DLL dropped to disk. A GALLIUM-associated variant established persistence via a scheduled task. The malware can stage collected data in a text file. More generally, the content places Poison Ivy among RAT families used for remote control, data theft, and espionage-oriented operations.
Poison Ivy appears across a wide range of threat activity and is explicitly noted as non-exclusive for attribution. Threat actors and clusters mentioned as using Poison Ivy include GALLIUM, TA428, Gaza Cybergang / Molerats, PKPLUG-related activity, Space Pirates, and actors involved in Vatican-focused espionage campaigns from 2014 to 2016. GALLIUM used a modified Poison Ivy variant that Microsoft assessed appeared unique to that group, with altered communications to reduce signature-based detection, and deployed it as a second-stage payload in attacks against telecommunications providers across Southeast Asia, Europe, and Africa after exploiting unpatched WildFly/JBoss servers. TA428 used Poison Ivy alongside Cotx RAT during Operation LagTime IT and laterally moved with EternalBlue. PKPLUG-related reporting tied Poison Ivy to espionage campaigns across Asia, including Myanmar and other politically sensitive targets, often via spear-phishing and DLL side-loading. The content also references Poison Ivy in attacks against Thai government targets, East Asian government agencies, Vatican and Catholic-linked entities, and in the RSA intrusion.
High-confidence indicators and artifacts directly mentioned in the content include the Operation LagTime IT Poison Ivy C2 IP 95.179.131[.]29; shared Poison Ivy password 3&U<9f*lZ>!MIQ in that campaign; and infrastructure overlaps involving vzglagtime[.]net subdomains in related TA428 activity. The content also notes Poison Ivy-related infrastructure overlap with Bookworm, FFRAT, PlugX, and Scieron, and references its use in conjunction with loaders such as FerryTrojan in Vatican-related campaigns. Overall, the provided material characterizes Poison Ivy as a broadly reused Windows RAT employed in espionage and intrusion operations across government, telecommunications, religious, and other sectors, often as a second-stage backdoor following phishing or exploitation.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
TA428 threat actors also delivered Poison Ivy malware payloads.
攻撃者はEternal Blueを悪用して同一ネットワーク上のいくつかのホストに移動することに成功すると、そのうちの1つのホスト上で興味深いマルウェアを動かし始めました。
The spreadsheet contained a zero-day exploit that installs a backdoor through an Adobe Flash vulnerability (CVE-2011-0609). As a side note, by now Adobe has released a patch for the zero-day, so it can no longer be used to inject malware onto patched machines. | In the case of the RSA attack the assault involved a variant of the Poison Ivy Trojan.
the callback domain 'www.adv138mail.com' was used by a Poison Ivy RAT in a July 2011 socially engineered email campaign
The second jar file had a MD5 of 3fbb7321d8610c6e2d990bb25ce34bec and exploited CVE-2013-1493. ... The jar that exploited CVE-2013-1493 dropped a 9002 RAT with a MD5 of 42bd5e7e8f74c15873ff0f4a9ce974cd. ... The exploit site at sunshop[.]com[.]tw previously hosted a different malicious jar file on April 2, 2013. This jar file had a MD5 of 51aff823274e9d12b1a9a4bbbaf8ce00. It exploited CVE-2013-1493 and dropped a Poison Ivy RAT.
China-linked actors using the exploit to deploy POISONIVY, dropped as a BAT file that downloads additional payloads.
CVE-2015-2545 is a vulnerability discovered in 2015 and corrected with Microsoft’s update MS15-099... enables an attacker to execute arbitrary code using a specially crafted EPS image file... exploited in the wild in August 2015... used in targeted attack by the Platinum group.
Details on Exploited Vulnerabilities ... CVE-2021-40444 Microsoft Windows ... YARA Rules ... reference = “... PrintNightmare and MSHTML exploits” ... $cve2 = “CVE-2021-40444”
Details on Exploited Vulnerabilities ... CVE-2021-1675 Microsoft Windows ... YARA Rules ... reference = “... PrintNightmare and MSHTML exploits” ... $cve1 = “CVE-2021-1675”
20 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
彼らはPoison IvyやCotx RATを使ってコンピュータのコントロールを得た後、更に侵害を深めるために横展開を行いました。
"Poison Ivy is a widely shared remote access tool (RAT) first identified in 2005. While Poison Ivy is widely used, the variant GALLIUM has been observed using is a modified version that appears to be unique to GALLIUM."
Tools include Molerat Loader, XtremeRAT, SharpStage, DropBook, Spark, Pierogi, PoisonIvy, and many others observed uniquely over the years.
Other publicly available malware seen in relation to PKPLUG activity includes Poison Ivy and Zupdax.
Earlier campaigns used legacy Poison Ivy RAT shellcode variants and ZxShell via spear-phishing and watering hole attacks.
Злоумышленники также используют и хорошо известное ВПО: PlugX, ShadowPad, Poison Ivy, модифицированный вариант PcShare и публичный шелл ReVBShell.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
Considering all the malware related to PKPLUG that Unit 42 has analyzed, the use of such exploits appears to be less common than a spear-phishing technique making use of social engineering to lure victims into running their malware.
We determined that the infection vector observed in this campaign was spear phishing, with emails originating from both free email accounts and compromised user accounts. Spear phishing emails included malicious .doc attachments that were actually RTF files saved with .doc file extensions. | Proofpoint researchers initially identified email campaigns with malicious RTF document attachments targeting East Asian government agencies in March 2019.
Unit 42 published research that reported attacks using the 9002 Trojan delivered through Google Drive. The download originated with a spear-phishing email containing a shortened URL that redirected multiple times before downloading a ZIP file hosted on Google Drive.
During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.
The spreadsheet contained a zero-day exploit that installs a backdoor... In the case of the RSA attack the assault involved a variant of the Poison Ivy Trojan.
The content of the website contained encoded VBScript that executed PowerShell commands ... as well as another encoded PowerShell script closely resembling PowerSploit ... that was responsible for decoding and launching a Poison Ivy payload.
During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions.
The content of the website contained encoded VBScript that executed PowerShell commands to download a Microsoft Word document from the same GeoCities site
The malicious RTF attachments exploited vulnerabilities in the Microsoft Equation Editor, specifically CVE-2018-0798, before downloading subsequent payloads.
During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
Catchamas creates three Registry keys to establish persistence by adding a Windows Service ... TEARDROP modified the Registry to create a Windows service for itself ... NightClub can modify the Registry to set the ServiceDLL for a service created by the malware for persistence.
During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.
Catchamas creates three Registry keys to establish persistence by adding a Windows Service ... TEARDROP modified the Registry to create a Windows service for itself ... NightClub can modify the Registry to set the ServiceDLL for a service created by the malware for persistence.
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
Spear phishing emails included malicious .doc attachments that were actually RTF files saved with .doc file extensions.
The contents of the file, assuming a victim clicked on the URL in the spear-phishing email, resembles the structure used in a technique known as AppLocker Bypass whereby trusted Windows executables can be used to execute malicious payloads.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
As part of the second stage, the group deploys customized Gh0st RAT and Poison Ivy malware payloads designed to evade detection... GALLIUM has modified the communication method used by the malware, likely to prevent detection through existing antimalware signatures.
The command and control structure of Cotx RAT is proxy aware. It utilizes wolfSSL for TLS encrypted communication.
Remote Access Trojans are programs that provide the capability to allow covert surveillance or the ability to gain unauthorized access to a victim PC... they provide the capability for an attacker to gain unauthorized remote access to the victim machine via specially configured communication protocols which are set up upon initial infection of the victim computer.
77 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
85 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as a non-exclusive tool that should not be used alone for APT10 attribution.
Shared frameworks such as PoisonIvy, ShadowPad, and more recently NosyDoor, have made attribution through this method increasingly difficult.
Legacy remote access trojan variant used in earlier APT-C-01 campaigns via spear-phishing and watering hole attacks.
A 2000s-era RAT discussed as part of a more advanced generation of remote access tools with builders, UPX packing, injection and hooking features, remote plugins, persistence, and mutex controls.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.