PupyRAT is an open-source, cross-platform remote access trojan and post-exploitation framework primarily written in Python. It is designed to provide remote control of compromised systems and has been observed operating on Windows, Linux, and Android. Its role in intrusion operations is typically as a flexible operator tool used after initial compromise, rather than as a self-propagating payload.
The malware has been used by multiple threat actors, including Iranian state-linked groups and other intrusion operators, in espionage-oriented campaigns. Reporting has associated its use with OilRig/APT34 and COBALT ILLUSION/APT35-related activity, including campaigns targeting government, private-sector, and energy-sector organizations. It has also been observed in exploitation chains following perimeter-device compromise, where attackers deployed remote access toolkits including PupyRAT to maintain access and conduct follow-on operations.
Observed delivery methods include malicious email attachments in phishing and job-themed lure campaigns, as well as deployment through fake or compromised websites in news media- and recruitment-themed operations. Once deployed, PupyRAT functions as a full-featured remote administration capability for adversaries, supporting interactive control and broader post-compromise activity. It is also notable in network detection research for distinctive TLS client behavior in some implementations, which has made it useful as an example of malware identifiable through JA3-style fingerprinting.
PupyRAT is widely recognized as a dual-use offensive security tool: legitimate for red-team or research contexts, but repeatedly repurposed in real-world malicious operations for covert access and post-exploitation.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Deployment of Remote Access Toolkits (RATs) – we observed various RATs including PupyRAT and GoMet | "NCC Group is today releasing three months of honeypot web traffic data related to the F5 CVE-2020-5902..." and "Network Signatures For F5 Big-IP TMUI hsqldb" with Snort rules referencing cve,2020-5902.
Deployment of Remote Access Toolkits (RATs) – we observed various RATs including PupyRAT and GoMet
Deployment of Remote Access Toolkits (RATs) – we observed various RATs including PupyRAT and GoMet
Deployment of Remote Access Toolkits (RATs) – we observed various RATs including PupyRAT and GoMet
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
APT33 至少从2019 年11 月下旬至1 月5 日期间针对欧洲能源部门的攻击活动,并且被安全厂商发现与欧洲能源部门组织的邮件服务器通信的PupyRAT 命令和控制(C2)服务器;
Hidden in the attachments was PupyRAT, an open source remote access trojan (RAT) that works across Android, Linux and Windows platforms.
"There are several un-referenced functions that appear to have been taken from the open source project PUPYRAT."
6 distinct techniques documented for this family, organized by ATT&CK tactic.
SecureWorks... sending out messages loaded with malware from legitimate email addresses belonging to one of Saudi Arabia's biggest IT suppliers, the National Technology Group, and an Egyptian IT services firm, ITWorx... analysis of the headers of the phishing emails indicated they originated from within the sender’s organization.
The OilRig hackers pushed those espionage tools over two fake Oxford University pages in November 2016, one claiming to offer jobs at the institution, the other a conference sign-up website... Both encouraged visitors to download documents... Once clicked, the crew's malware, named Helminth, would run.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cross-platform RAT and post-exploitation tool with encrypted DNS C2, mentioned in the DecoyDog overlap discussion.
Remote access trojan (often used as a red-team tool) whose TLS ClientHello characteristics (cipher/extension ordering) can produce a distinctive JA3 fingerprint useful for network detection/hunting.
Open-source RAT framework referenced as a code source/template; portions of its code appear repurposed within CLEANPULSE (unreferenced functions), suggesting code reuse rather than direct deployment of the full RAT.
Remote Access Trojan observed as a payload delivered post-exploitation of F5 Big-IP/Citrix devices to provide remote control/persistence.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.