Ping is identified in the provided content as one of the major cryptocurrency drainer families active in 2024. The content places Ping within the broader drainer ecosystem: phishing operations that trick victims into approving malicious smart-contract transactions, enabling attackers to transfer assets from victims’ wallets. These campaigns primarily target smart-contract-enabled blockchains such as Ethereum, Base, Polygon, and Optimism, with the broader ecosystem also expanding to Solana and, according to the content, even Bitcoin-targeting variants. Common infection and delivery vectors for this malware category include fake airdrops or token offers, cloned phishing websites that imitate legitimate crypto projects, malicious JavaScript embedded in those sites, lookalike domains, and traffic generation through ads, social media, cloned support channels, Telegram, and Discord. The content further describes the surrounding criminal market as a Drainer-as-a-Service ecosystem involving developers, operators, workers, recruiters, and traffic specialists, often using Telegram bots and supporting infrastructure to rapidly deploy campaigns. No Ping-specific technical indicators, infrastructure, or unique behavioral details beyond its identification as an active 2024 drainer are directly provided in the content. The name also appears in unrelated ATT&CK-style references to the legitimate network utility used for remote system discovery; however, the malware-relevant context here is the cryptocurrency drainer family named Ping.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named crypto drainer active in 2024, part of the drainer-as-a-service ecosystem targeting cryptocurrency users through phishing pages and malicious wallet approvals.
A standard network utility used to identify reachable remote systems within a network.
ICMP utility used to test reachability; commonly used for host discovery.
Native ICMP utility used for host discovery and reachability testing.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.