PITSTOP is malware observed in exploitation of Ivanti Connect Secure appliances by UNC5325, a suspected Chinese espionage operator. Mandiant reported UNC5325 deploying PITSTOP alongside LITTLELAMB.WOOLTEA, PITDOG, PITJET, and PITHOOK during activity involving exploitation of Ivanti vulnerabilities including CVE-2024-21893, often chained with CVE-2024-21887. High-confidence behavior described for PITSTOP includes communication over TLS and listening on a Unix domain socket at /data/runtime/cockpit/wd.fd, indicating use of encrypted communications and local inter-process communication on compromised appliances. The broader UNC5325 activity targeted Ivanti appliances across multiple industry verticals, including the U.S. defense industrial base, and involved attempts to establish persistence and evade detection using custom malware and living-off-the-land techniques.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Mandiant observed ... development of a mitigation bypass exploit targeting CVE-2024-21893 ... The mitigation bypass is now tracked as CVE-2024-21893. It is a server-side request forgery (SSRF) vulnerability in the SAML component of Ivanti Connect Secure (CS), Policy Secure (PS), and Neurons for Zero Trust Access (NZTA) appliances... Mandiant identified active exploitation of CVE-2024-21893 by UNC5325 as early as Jan. 19, 2024... threat actors chaining the SSRF vulnerability with ... CVE-2024-21887...
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
UNC5325 has been observed deploying LITTLELAMB.WOOLTEA, PITSTOP, PITDOG, PITJET, and PITHOOK.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors using SSL, TLS, HTTPS, RSA, AES, Blowfish, RC4, ECIES, Diffie-Hellman, OpenSSL, WolfSSL, and mutual TLS to protect command and control traffic.
Multiple malware families and intrusion sets are described as encrypting C2 traffic using SSL/TLS/HTTPS (e.g., "used HTTPS for command and control", "encrypts C2 communications with TLS", "uses SSL for encrypting C2 communications", "TLS-encrypted WebSocket Protocol (WSS) for C2").
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor that listens on a Unix domain socket for communication.
Malware that can communicate over TLS.
Malware that listens over a Unix domain socket for local IPC.
Can communicate over TLS.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.