Skip to main content
Mallory
MalwareRansomwareUsed by 3 actors

PuTTY

PuTTY is a publicly available SSH client and related remote access utility suite that includes components such as Plink (PuTTY Link). In the provided reporting, it appears primarily as a legitimate dual-use tool abused by multiple threat actors rather than as a distinct malware family. North Korea-linked actors including Stonefly/Andariel/Onyx Sleet and Moonstone Sleet have used PuTTY or trojanized PuTTY in operations. Microsoft reported that in early August 2023 Moonstone Sleet delivered a trojanized version of PuTTY via LinkedIn, Telegram, and developer freelancing platforms; the lure often used a ZIP containing putty.exe and url.txt with an IP address and password, and entering those values caused the trojanized binary to decrypt and execute an embedded payload, initiating a multi-stage chain involving SplitLoader and follow-on loaders. Separately, reporting on Andariel states the group has used PuTTY and WinSCP to exfiltrate data to North Korea-controlled servers via FTP and other protocols, and Symantec observed Stonefly using PuTTY and Plink for SSH connectivity during financially motivated intrusions. Arctic Wolf also documented threat actors exploiting Qlik Sense to deploy Cactus ransomware tooling, including downloading a Plink binary renamed to putty.exe, using it to establish an RDP tunnel over SSH on port 443 with remote forwarding to 127.0.0.1:3389 via 45.61.147[.]176:50400; related infrastructure and payload locations included zohoservice[.]net, 216.107.136[.]46, and 144.172.122[.]30, and Arctic Wolf provided SHA-256 828e81aa16b2851561fff6d3127663ea2d1d68571f06cbd732fdf5672086924d for the observed Plink sample. Cisco Talos also noted PuTTY was used for credential exfiltration in the first wave of the 2023 ToyMaker/UNC961 campaign before a later handoff to the Cactus ransomware group.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
ToyMaker

Differences in TTPs... operators conducting initial access relied on PuTTY for credential exfiltration...

via talos intelligence blogblog.talosintelligence.com
Andariel

...observed using the utilities PuTTY and WinSCP to exfiltrate data...

via cisa alertscisa.gov
Lazarus

Microsoft observed Moonstone Sleet delivering a trojanized version of PuTTY

via microsoft security blogmicrosoft.com
MITRE ATT&CK

Techniques & procedures

16 distinct techniques documented for this family, organized by ATT&CK tactic.

T1583Acquire InfrastructureEvidence1

T1583 Acquire Infrastructure QuadSwitcher acquired infrastructure to host their tooling.

T1588.002ToolEvidence5

The content repeatedly states that threat actors 'obtained,' 'acquired,' or 'used' publicly available, open-source, legitimate, or modified tools such as Mimikatz, Cobalt Strike, PsExec, Empire, Impacket, and many others.

T1608.002Upload ToolEvidence1

T1608.002 Stage Capabilities: Upload Tool The Play gang uploaded the third-party tools it uses to a dedicated server to be used during intrusions.

Persistence

1 technique
T1112Modify RegistryEvidence1

the .msi installer also contained five Windows Registry ( .reg ) files, which it could use to make modifications to the computer

Stealth

2 techniques
T1036MasqueradingEvidence1
TacticStealth

In the case of the DLL, the executable is a PuTTY client with a valid code-signing certificate. The binary distributed via JavaScript is an Inno Setup installer for an Electron application.

T1218System Binary Proxy ExecutionEvidence1
TacticStealth

At the end of August 2024, QuadSwitcher compromised a technology company in Western Europe, downloading PuTTY from http://130.185.75[.]198:8000/plink.exe using certutil.exe ... The threat actor also downloaded MeshAgent ... also via certutil.exe.

T1112Modify RegistryEvidence1

the .msi installer also contained five Windows Registry ( .reg ) files, which it could use to make modifications to the computer

T1555Credentials from Password StoresEvidence1

Credential theft is a primary objective. The group uses various techniques to perform this core function, including dumping the Local Security Authority Subsystem Service (LSASS) memory and exfiltrating the NTDS.dit Active Directory database, and capturing credentials stored in browsers and SSH clients like PuTTY and OpenSSH.

Lateral Movement

2 techniques
T1021Remote ServicesEvidence1

"The threat actor used RDP with valid account credentials for lateral movement..."

T1021.004SSHEvidence5

The threat actor used Plink and PuTTY for lateral movement. Artifacts of Plink were used for encrypted sessions in the system registry hive.

T1071Application Layer ProtocolEvidence2

T1071 Application Layer Protocol In Play intrusions, payloads are retrieved via HTTP.

T1071.002File Transfer ProtocolsEvidence1

MirrorFace has used the the PuTTY suite Secure Copy Protocol (SCP) client for file transfer.

T1219Remote Access ToolsEvidence2

INC Ransom has used AnyDesk and PuTTY on compromised systems.

T1572Protocol TunnelingEvidence2

“They also use tunneling tools such as 3Proxy, PLINK, and Stunnel... [T1090, T1071].”

Exfiltration

3 techniques
T1041Exfiltration Over C2 ChannelEvidence1

ADVSTORESHELL exfiltrates data over the same channel used for C2... Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers... numerous malware and groups sent victim data, files, credentials, or host information over existing C2 channels.

T1048Exfiltration Over Alternative ProtocolEvidence2

“...used the utilities PuTTY and WinSCP to exfiltrate data... via File Transfer Protocol (FTP) and other protocols [T1048].”

T1567.002Exfiltration to Cloud StorageEvidence1

"Cloud storage misuse: Operators have logged into cloud storage services such as MEGA directly from compromised networks, uploading data with tools like WinSCP and PuTTY."

INDICATORS OF COMPROMISE

IOCs tracked for this family

3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Hashes
3 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

TypeValueLatest sighting
hash.sha256●●●●●●●●●●●●View more in app3 years ago
hash.sha256●●●●●●●●●●●●View more in app3 years ago
hash.sha256●●●●●●●●●●●●View more in app3 years ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching3

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution3

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping16

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.