PingPong is a Linux backdoor associated with the China-nexus espionage group LIMINAL PANDA. It passively monitors ICMP traffic for a specified secret trigger value and, when triggered, establishes a reverse shell on the compromised host. PingPong uses ICMP echo traffic as a covert channel for command-and-control and can support data exfiltration, allowing remote access to blend with commonly permitted diagnostic network traffic. LIMINAL PANDA has deployed the backdoor in operations against telecommunications networks, particularly infrastructure involved in mobile and GPRS services, to support long-term access and signals-intelligence-oriented espionage.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
PingPong, a Linux backdoor that uses ICMP to listen for specific secret value within ICMP packets, allowing it to establish reverse shell connections stealthily.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as an associated analytic story; the content does not provide behavioral details beyond implying it is a backdoor associated with command-and-control activity.
Referenced for comparison: an ICMP-triggered backdoor family that actively initiates a C2 connection after receiving a trigger ICMP echo packet.
A legacy backdoor that provides unauthorized remote access to compromised systems and uses ICMP/ping traffic as a covert command-and-control or data exfiltration channel.
Linux backdoor that monitors ICMP packets for a secret value and then stealthily establishes reverse-shell access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.