PipeMon is a modular Windows backdoor attributed in the provided content to the Winnti Group and reported as used against several video gaming companies. It persists by registering a malicious DLL as an alternative Print Processor so it is loaded when the Windows print spooler service starts. The malware stores its encrypted payload in the Registry, specifically under HKLM\SOFTWARE\Microsoft\Print\Components, and its modules may be written to disk using seemingly benign names, including file extensions associated with a popular word processor. PipeMon’s installer can use UAC bypass techniques to install the payload. Execution and loading behavior described in the content includes use of CreateProcess for the first stage with a decryption password passed as an argument, LoadLibrary to load the installer, reflective DLL loading, custom shellcode-based module loading, and injection of modules into various processes via reflective DLL loading. PipeMon can check for the presence of ESET and Kaspersky security software, and it can collect and send time zone information from a compromised host to command-and-control infrastructure. Its communication module can use a custom protocol based on TLS over TCP. PipeMon, its installer, and associated tools were signed with stolen code-signing certificates.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In February 2020, we discovered a new, modular backdoor, which we named PipeMon. Persisting as a Print Processor, it was used by the Winnti Group against several video gaming companies...
26 distinct techniques documented for this family, organized by ATT&CK tactic.
"ADVSTORESHELL is capable of starting a process using CreateProcess"; "build_downer has the ability to use the WinExec API"; "Aria-body has the ability to launch files using ShellExecute"
Astaroth uses the LoadLibraryExW() function to load additional modules. Attor's dispatcher can execute additional plugins by loading the respective DLLs. ... LightSpy's main executable and module .dylib binaries are loaded using ... dlopen() ... dlsym() ... RotaJakiro uses ... .so files ... using dlopen() and dlsym().
...uses the LoadLibraryExW() function to load additional modules... execute additional plugins by loading the respective DLLs... loaded and executed DLLs in memory during runtime... loads a dynamic library (.dylib file) using dlopen() and obtains a function pointer... using dlopen() and dlsym()... calls LoadLibrary then executes exports from a DLL.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
“Sandworm Team used an arbitrary system service to load at system boot for persistence for Industroyer… replaced the ImagePath registry value of a Windows service with a new backdoor binary… [multiple groups/malware] creating a service / installing as a service / modifying service configurations for persistence.”
Donut includes subprojects that enumerate and identify information about Process Injection candidates. PipeMon can iterate over the running processes to find a suitable injection target.
"If not, it will attempt to obtain such privileges using token impersonation..."
“Sandworm Team used an arbitrary system service to load at system boot for persistence for Industroyer… replaced the ImagePath registry value of a Windows service with a new backdoor binary… [multiple groups/malware] creating a service / installing as a service / modifying service configurations for persistence.”
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
Examples include: “ComRAT has encrypted and stored its orchestrator code in the Registry…”, “ShadowPad maintains a configuration block and virtual file system in the Registry.”, and “QakBot can store its configuration information…under HKCU\Software\Microsoft.”
Examples throughout the content include 'encrypted payloads decrypted and executed in memory,' 'encrypts its configuration file,' 'AES-encrypted resource,' 'RC4 encrypted embedded scripts,' and 'payload includes an encrypted main component.'
During the 2016 Ukraine Electric Power Attack, DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files.
APT28 has changed extensions on files containing exfiltrated data to make them appear benign.
Donut includes subprojects that enumerate and identify information about Process Injection candidates. PipeMon can iterate over the running processes to find a suitable injection target.
"If not, it will attempt to obtain such privileges using token impersonation..."
The content repeatedly describes malware and threat actors decoding, decrypting, deobfuscating, or unpacking payloads, strings, configuration data, commands, and C2 responses prior to execution or use.
...uses the LoadLibraryExW() function to load additional modules... execute additional plugins by loading the respective DLLs... loaded and executed DLLs in memory during runtime... loads a dynamic library (.dylib file) using dlopen() and obtains a function pointer... using dlopen() and dlsym()... calls LoadLibrary then executes exports from a DLL.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
The content repeatedly describes malware and threat actors using commands and APIs such as ipconfig /all, ifconfig, arp -a, route print, nbtstat, netsh, GetAdaptersInfo, and GetIpNetTable to gather IP addresses, MAC addresses, DNS, DHCP, gateways, routing tables, ARP cache, proxy settings, domains, and network adapter/interface details.
The content repeatedly describes malware and threat actors obtaining lists of running processes, using utilities such as tasklist, ps, WMI, Get-Process, CreateToolhelp32Snapshot, EnumProcesses, and similar APIs/commands to enumerate active processes on victim systems.
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
Multiple malware and threat groups are described as collecting/deriving local system time, date, timestamp, tick count, or time zone (e.g., "used time /t and net time \ip/hostname for system time discovery"; "collects the timestamp from the victim’s machine"; "can collect the time zone information from the system").
34 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
26 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only to note certificate overlap with some signed Zupdax-related samples, suggesting possible linkage to Winnti-associated signing infrastructure; no PipeMon functionality described here.
PipeMon is a modular Windows backdoor used for long-term access. It persists by registering a malicious DLL as a Windows Print Processor (under the Print Spooler), stores/encrypts payloads and modules (disk and/or registry depending on variant), injects modules into selected processes, and communicates with C2 over TLS/TCP (port 443) using an additional RC4/XOR layer and optional compression. It supports on-demand module installation and commands including system/network/process discovery, RDP info collection, and DLL injection.
PipeMon and related tooling were signed with stolen code-signing certificates.
Backdoor that persists by registering a malicious Print Processor DLL loaded by the print spooler service.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.